-
Notifications
You must be signed in to change notification settings - Fork 0
Code Security: ecosystem dependency-CVE audit (2026-07-30) — remediation status + residuals #679
Copy link
Copy link
Open
Labels
area: authAuthentication, authorization, identity, or tenant isolationAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainarea: dependenciesDependency or lockfile maintenanceDependency or lockfile maintenancearea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionmaintenancepriority: criticalImmediate blocker, P0, urgent deadlock, or critical incidentImmediate blocker, P0, urgent deadlock, or critical incidentstatus: triagedOpen issue has an organization taxonomy assignmentOpen issue has an organization taxonomy assignmenttype: maintenanceMaintenance, build, dependency, or operational upkeepMaintenance, build, dependency, or operational upkeep
Description
Activity
Metadata
Metadata
Assignees
Labels
area: authAuthentication, authorization, identity, or tenant isolationAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainarea: dependenciesDependency or lockfile maintenanceDependency or lockfile maintenancearea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionmaintenancepriority: criticalImmediate blocker, P0, urgent deadlock, or critical incidentImmediate blocker, P0, urgent deadlock, or critical incidentstatus: triagedOpen issue has an organization taxonomy assignmentOpen issue has an organization taxonomy assignmenttype: maintenanceMaintenance, build, dependency, or operational upkeepMaintenance, build, dependency, or operational upkeep
Centralized Code-Security governance record for a dependency-CVE sweep across the ecosystem's Python (
pip-audit) and Node (npm/pnpm audit) lockfiles on 2026-07-30. Filed so findings live in the repo/Project rather than private agent memory, and so the higher-risk residuals get deliberate handling instead of an under-verified auto-bump.Remediated this pass (fixed at base, verified, pushed)
2afce4e)pydantic-settings 2.12.0GHSA-4xgf-cpjx-pc3j;pyasn1 0.6.3PYSEC-2026-3455/3456/3457--require-hashesinstall hash-valid,app.mainimports,mypy68 files clean4696a13)postcss <=8.5.17GHSA-r28c-9q8g-f849 (high)overrides→^8.5.18(8.5.25)typecheckclean,test61 passed,security:scan0 vulnsOpen residuals (severity-classified, needing care or follow-up)
packages/webnext-auth5.0.0-beta.30 → beta.32 (+@auth/core→ 0.41.3)brace-expansion<1.1.16 (95 dev paths)overrides→>=1.1.16frontendquickcheckafter bumpsetuptools 82.0.1PYSEC-2026-3447ecdsa 0.19.2PYSEC-2026-1325--ignore-unfixed; track for a future releaseClean (no known vulnerabilities)
contextual-orchestrator, semantic-data-portal (Python); naruon frontend (pnpm).
Note: all remediation PRs above are currently gated from merging by the org-wide
opencode-review: exhaustedstate (the reviewer-provider credential is not yet provisioned), tracked separately at #624 — the fixes are staged and verified, awaiting pipeline recovery.