Skip to content

chore(security): resolve open Dependabot/Trivy alerts and clean up CodeQL noise - #5938

Open
ToddHebebrand wants to merge 1 commit into
mainfrom
chore/gh-security-sweep
Open

ToddHebebrand wants to merge 1 commit into
mainfrom
chore/gh-security-sweep

Conversation

@ToddHebebrand

Copy link
Copy Markdown
Collaborator

Summary

Dismissed out-of-band with reasons: 30 CodeQL alerts (false positives / accepted tradeoffs), 5 Dependabot alerts with no fix path (adm-zip, glib via tauri gtk 0.18, rand 0.7 build-dep), 1 secret-scanning alert (test fixture).

Verification

  • pnpm install clean; executorApkPolicy.test.ts 11/11 pass
  • go build ./... in agent OK
  • cargo check OK for helper and viewer
  • decode-uri-component 0.2 → 0.5 sits under react-navigation (mobile); the iOS build job is the gate for that one

🤖 Generated with Claude Code

…deQL noise

Bump vulnerable transitive deps via pnpm overrides (dompurify 3.4.13,
sanitize-html 2.17.7, qs 6.16.0, postcss 8.5.23, fflate 0.8.3,
postcss-selector-parser 6.1.3, decode-uri-component 0.5.0), esbuild
override in e2e-tests, golang.org/x/crypto 0.56.0 in the agent, and
serde_with 3.21.0 in the helper/viewer Cargo locks.

Replace execFileSync('cat') with readFileSync in executorApkPolicy.test.ts
(js/unnecessary-use-of-cat).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 15, 2026

Copy link
Copy Markdown

Deploying breeze with  Cloudflare Pages  Cloudflare Pages

Latest commit: e6e83c8
Status: ✅  Deploy successful!
Preview URL: https://331e395f.breeze-9te.pages.dev
Branch Preview URL: https://chore-gh-security-sweep.breeze-9te.pages.dev

View logs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant