Automated weekly security sweep — last rewritten 2026-08-31 07:30 UTC (runs).
This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them with a written reason (this repo's .gitleaks.toml for secrets, an inline # nosemgrep: <rule-id> -- <reason> for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.
alembic/env.py:62opt.security-rules.fabled-sql-string-interpolation — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.
alembic/versions/0069_default_siglip2.py:31opt.security-rules.fabled-sql-string-interpolation — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.
alembic/versions/0088_reconcile_models_with_schema.py:99opt.security-rules.fabled-sql-string-interpolation — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation. WARNING — useful, precision not yet proven (2):
frontend/src/components/modal/ProvenancePanel.vue:62opt.security-rules.fabled-vue-v-html — v-html renders raw HTML into the DOM. Legitimate only when the value is server-escaped (FabledForge's Reader is). Confirm the source is escaped server-side; if it is user-supplied and unescaped this i
frontend/src/components/posts/PostCard.vue:87opt.security-rules.fabled-vue-v-html — v-html renders raw HTML into the DOM. Legitimate only when the value is server-escaped (FabledForge's Reader is). Confirm the source is escaped server-side; if it is user-supplied and unescaped this i
HIGH CVE-2026-58049 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-64830 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-64831 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-64832 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-64834 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-64835 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-66036 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-66039 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-66040 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-66041 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-70628 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-70632 — ffmpeg 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-41992 — gzip 1.13-1 (no fix released)
HIGH CVE-2026-54369 — libacl1 2.3.2-2+b1 (no fix released)
HIGH CVE-2026-58049 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-64830 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-64831 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-64832 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-64834 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-64835 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-66036 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-66039 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-66040 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-66041 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-70628 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-70632 — libavcodec61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-58049 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-64830 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-64831 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-64832 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-64834 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-64835 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-66036 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-66039 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-66040 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-66041 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-70628 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-70632 — libavdevice61 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-58049 — libavfilter10 7:7.1.5-0+deb13u1 (no fix released)
HIGH CVE-2026-64830 — libavfilter10 7:7.1.5-0+deb13u1 (no fix released) …and 146 more line(s) truncated — run the scanner locally or trigger the sweep with only= for the full list.
Coverage & limits
All four scanners ran with nothing skipped.
<!-- fabledsentry-security-dashboard -->
_Automated weekly security sweep — last rewritten 2026-08-31 07:30 UTC ([runs](https://git.fabledsword.com/bvandeusen/CI-runner/actions))._
This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them **with a written reason** (this repo's `.gitleaks.toml` for secrets, an inline `# nosemgrep: <rule-id> -- <reason>` for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.
## Secrets (gitleaks)
- `backend/app/services/pixiv_client.py:71` — rule `generic-api-key`, commit `86ae3969` 2026-07-03T13:36:54Z
- `backend/app/services/pixiv_client.py:72` — rule `generic-api-key`, commit `86ae3969` 2026-07-03T13:36:54Z
- `extension/background/background.js:14` — rule `generic-api-key`, commit `df82abe7` 2026-05-24T03:34:11Z
- `extension/background/background.js:15` — rule `generic-api-key`, commit `df82abe7` 2026-05-24T03:34:11Z
## Code findings (semgrep, curated family ruleset)
**ERROR — believed-real on this family's code (3):**
- `alembic/env.py:62` `opt.security-rules.fabled-sql-string-interpolation` — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.
- `alembic/versions/0069_default_siglip2.py:31` `opt.security-rules.fabled-sql-string-interpolation` — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.
- `alembic/versions/0088_reconcile_models_with_schema.py:99` `opt.security-rules.fabled-sql-string-interpolation` — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.
**WARNING — useful, precision not yet proven (2):**
- `frontend/src/components/modal/ProvenancePanel.vue:62` `opt.security-rules.fabled-vue-v-html` — v-html renders raw HTML into the DOM. Legitimate only when the value is server-escaped (FabledForge's Reader is). Confirm the source is escaped server-side; if it is user-supplied and unescaped this i
- `frontend/src/components/posts/PostCard.vue:87` `opt.security-rules.fabled-vue-v-html` — v-html renders raw HTML into the DOM. Legitimate only when the value is server-escaped (FabledForge's Reader is). Confirm the source is escaped server-side; if it is user-supplied and unescaped this i
## Dependency CVEs (osv-scanner)
- `idna 3.9.0` (PyPI, `agent/requirements.txt`): [GHSA-65pc-fj4g-8rjx](https://osv.dev/vulnerability/GHSA-65pc-fj4g-8rjx), [PYSEC-2026-215](https://osv.dev/vulnerability/PYSEC-2026-215)
- `pillow 9.5.0` (PyPI, `agent/requirements.txt`): [GHSA-3f63-hfp8-52jq](https://osv.dev/vulnerability/GHSA-3f63-hfp8-52jq), [GHSA-44wm-f244-xhp3](https://osv.dev/vulnerability/GHSA-44wm-f244-xhp3), [GHSA-45hq-cxwh-f6vc](https://osv.dev/vulnerability/GHSA-45hq-cxwh-f6vc), [GHSA-4x4j-2g7c-83w6](https://osv.dev/vulnerability/GHSA-4x4j-2g7c-83w6), [GHSA-5x94-69rx-g8h2](https://osv.dev/vulnerability/GHSA-5x94-69rx-g8h2), [GHSA-62p4-gmf7-7g93](https://osv.dev/vulnerability/GHSA-62p4-gmf7-7g93), [GHSA-6r8x-57c9-28j4](https://osv.dev/vulnerability/GHSA-6r8x-57c9-28j4), [GHSA-8ghj-p4vj-mr35](https://osv.dev/vulnerability/GHSA-8ghj-p4vj-mr35), [GHSA-8v84-f9pq-wr9x](https://osv.dev/vulnerability/GHSA-8v84-f9pq-wr9x), [GHSA-9hw9-ch79-4vh6](https://osv.dev/vulnerability/GHSA-9hw9-ch79-4vh6), [GHSA-fj7v-r99m-22gq](https://osv.dev/vulnerability/GHSA-fj7v-r99m-22gq), [GHSA-j7hp-h8jx-5ppr](https://osv.dev/vulnerability/GHSA-j7hp-h8jx-5ppr), [GHSA-jjj6-mw9f-p565](https://osv.dev/vulnerability/GHSA-jjj6-mw9f-p565), [GHSA-phj9-mv4w-65pm](https://osv.dev/vulnerability/GHSA-phj9-mv4w-65pm), [GHSA-r73j-pqj5-w3x7](https://osv.dev/vulnerability/GHSA-r73j-pqj5-w3x7), [GHSA-vjc4-5qp5-m44j](https://osv.dev/vulnerability/GHSA-vjc4-5qp5-m44j), [GHSA-wjx4-4jcj-g98j](https://osv.dev/vulnerability/GHSA-wjx4-4jcj-g98j), [GHSA-xj96-63gp-2gmr](https://osv.dev/vulnerability/GHSA-xj96-63gp-2gmr), [PYSEC-2023-175](https://osv.dev/vulnerability/PYSEC-2023-175), [PYSEC-2023-227](https://osv.dev/vulnerability/PYSEC-2023-227), [PYSEC-2026-165](https://osv.dev/vulnerability/PYSEC-2026-165), [PYSEC-2026-1793](https://osv.dev/vulnerability/PYSEC-2026-1793), [PYSEC-2026-1794](https://osv.dev/vulnerability/PYSEC-2026-1794), [PYSEC-2026-2253](https://osv.dev/vulnerability/PYSEC-2026-2253), [PYSEC-2026-2254](https://osv.dev/vulnerability/PYSEC-2026-2254), [PYSEC-2026-2255](https://osv.dev/vulnerability/PYSEC-2026-2255), [PYSEC-2026-2256](https://osv.dev/vulnerability/PYSEC-2026-2256), [PYSEC-2026-2257](https://osv.dev/vulnerability/PYSEC-2026-2257), [PYSEC-2026-2874](https://osv.dev/vulnerability/PYSEC-2026-2874), [PYSEC-2026-3451](https://osv.dev/vulnerability/PYSEC-2026-3451), [PYSEC-2026-3453](https://osv.dev/vulnerability/PYSEC-2026-3453), [PYSEC-2026-3454](https://osv.dev/vulnerability/PYSEC-2026-3454), [PYSEC-2026-3493](https://osv.dev/vulnerability/PYSEC-2026-3493), [PYSEC-2026-3494](https://osv.dev/vulnerability/PYSEC-2026-3494), [PYSEC-2026-3495](https://osv.dev/vulnerability/PYSEC-2026-3495), [PYSEC-2026-3496](https://osv.dev/vulnerability/PYSEC-2026-3496), [PYSEC-2026-457](https://osv.dev/vulnerability/PYSEC-2026-457)
- `torch 1.8.1` (PyPI, `agent/requirements.txt`): [GHSA-3749-ghw9-m3mg](https://osv.dev/vulnerability/GHSA-3749-ghw9-m3mg), [GHSA-47fc-vmwq-366v](https://osv.dev/vulnerability/GHSA-47fc-vmwq-366v), [GHSA-53q9-r3pm-6pq6](https://osv.dev/vulnerability/GHSA-53q9-r3pm-6pq6), [GHSA-5pcm-hx3q-hm94](https://osv.dev/vulnerability/GHSA-5pcm-hx3q-hm94), [GHSA-887c-mr87-cxwp](https://osv.dev/vulnerability/GHSA-887c-mr87-cxwp), [GHSA-c678-jfcj-6jmf](https://osv.dev/vulnerability/GHSA-c678-jfcj-6jmf), [GHSA-f4hp-rmr7-r7v8](https://osv.dev/vulnerability/GHSA-f4hp-rmr7-r7v8), [GHSA-pg7h-5qx3-wjr3](https://osv.dev/vulnerability/GHSA-pg7h-5qx3-wjr3), [GHSA-qfhq-4f3w-5fph](https://osv.dev/vulnerability/GHSA-qfhq-4f3w-5fph), [GHSA-rrmf-rvhw-rf47](https://osv.dev/vulnerability/GHSA-rrmf-rvhw-rf47), [GHSA-vgrw-7cvw-pwgx](https://osv.dev/vulnerability/GHSA-vgrw-7cvw-pwgx), [GHSA-x3gm-94wq-g975](https://osv.dev/vulnerability/GHSA-x3gm-94wq-g975), [PYSEC-2022-43015](https://osv.dev/vulnerability/PYSEC-2022-43015), [PYSEC-2024-250](https://osv.dev/vulnerability/PYSEC-2024-250), [PYSEC-2024-251](https://osv.dev/vulnerability/PYSEC-2024-251), [PYSEC-2024-252](https://osv.dev/vulnerability/PYSEC-2024-252), [PYSEC-2024-259](https://osv.dev/vulnerability/PYSEC-2024-259), [PYSEC-2025-191](https://osv.dev/vulnerability/PYSEC-2025-191), [PYSEC-2025-198](https://osv.dev/vulnerability/PYSEC-2025-198), [PYSEC-2025-203](https://osv.dev/vulnerability/PYSEC-2025-203), [PYSEC-2025-204](https://osv.dev/vulnerability/PYSEC-2025-204), [PYSEC-2025-205](https://osv.dev/vulnerability/PYSEC-2025-205), [PYSEC-2025-206](https://osv.dev/vulnerability/PYSEC-2025-206), [PYSEC-2025-207](https://osv.dev/vulnerability/PYSEC-2025-207), [PYSEC-2025-208](https://osv.dev/vulnerability/PYSEC-2025-208), [PYSEC-2025-209](https://osv.dev/vulnerability/PYSEC-2025-209), [PYSEC-2025-41](https://osv.dev/vulnerability/PYSEC-2025-41), [PYSEC-2026-139](https://osv.dev/vulnerability/PYSEC-2026-139), [PYSEC-2026-1970](https://osv.dev/vulnerability/PYSEC-2026-1970), [PYSEC-2026-2286](https://osv.dev/vulnerability/PYSEC-2026-2286)
## Published image (trivy)
- **HIGH** CVE-2026-58049 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-64830 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-64831 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-64832 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-64834 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-64835 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-66036 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-66039 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-66040 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-66041 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-70628 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-70632 — `ffmpeg 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-41992 — `gzip 1.13-1` (no fix released)
- **HIGH** CVE-2026-54369 — `libacl1 2.3.2-2+b1` (no fix released)
- **HIGH** CVE-2026-58049 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-64830 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-64831 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-64832 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-64834 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-64835 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-66036 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-66039 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-66040 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-66041 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-70628 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-70632 — `libavcodec61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-58049 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-64830 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-64831 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-64832 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-64834 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-64835 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-66036 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-66039 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-66040 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-66041 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-70628 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-70632 — `libavdevice61 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-58049 — `libavfilter10 7:7.1.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-64830 — `libavfilter10 7:7.1.5-0+deb13u1` (no fix released)
_…and 146 more line(s) truncated — run the scanner locally or trigger the sweep with `only=` for the full list._
## Coverage & limits
- All four scanners ran with nothing skipped.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Automated weekly security sweep — last rewritten 2026-08-31 07:30 UTC (runs).
This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them with a written reason (this repo's
.gitleaks.tomlfor secrets, an inline# nosemgrep: <rule-id> -- <reason>for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.Secrets (gitleaks)
backend/app/services/pixiv_client.py:71— rulegeneric-api-key, commit86ae39692026-07-03T13:36:54Zbackend/app/services/pixiv_client.py:72— rulegeneric-api-key, commit86ae39692026-07-03T13:36:54Zextension/background/background.js:14— rulegeneric-api-key, commitdf82abe72026-05-24T03:34:11Zextension/background/background.js:15— rulegeneric-api-key, commitdf82abe72026-05-24T03:34:11ZCode findings (semgrep, curated family ruleset)
ERROR — believed-real on this family's code (3):
alembic/env.py:62opt.security-rules.fabled-sql-string-interpolation— SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.alembic/versions/0069_default_siglip2.py:31opt.security-rules.fabled-sql-string-interpolation— SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.alembic/versions/0088_reconcile_models_with_schema.py:99opt.security-rules.fabled-sql-string-interpolation— SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.WARNING — useful, precision not yet proven (2):
frontend/src/components/modal/ProvenancePanel.vue:62opt.security-rules.fabled-vue-v-html— v-html renders raw HTML into the DOM. Legitimate only when the value is server-escaped (FabledForge's Reader is). Confirm the source is escaped server-side; if it is user-supplied and unescaped this ifrontend/src/components/posts/PostCard.vue:87opt.security-rules.fabled-vue-v-html— v-html renders raw HTML into the DOM. Legitimate only when the value is server-escaped (FabledForge's Reader is). Confirm the source is escaped server-side; if it is user-supplied and unescaped this iDependency CVEs (osv-scanner)
idna 3.9.0(PyPI,agent/requirements.txt): GHSA-65pc-fj4g-8rjx, PYSEC-2026-215pillow 9.5.0(PyPI,agent/requirements.txt): GHSA-3f63-hfp8-52jq, GHSA-44wm-f244-xhp3, GHSA-45hq-cxwh-f6vc, GHSA-4x4j-2g7c-83w6, GHSA-5x94-69rx-g8h2, GHSA-62p4-gmf7-7g93, GHSA-6r8x-57c9-28j4, GHSA-8ghj-p4vj-mr35, GHSA-8v84-f9pq-wr9x, GHSA-9hw9-ch79-4vh6, GHSA-fj7v-r99m-22gq, GHSA-j7hp-h8jx-5ppr, GHSA-jjj6-mw9f-p565, GHSA-phj9-mv4w-65pm, GHSA-r73j-pqj5-w3x7, GHSA-vjc4-5qp5-m44j, GHSA-wjx4-4jcj-g98j, GHSA-xj96-63gp-2gmr, PYSEC-2023-175, PYSEC-2023-227, PYSEC-2026-165, PYSEC-2026-1793, PYSEC-2026-1794, PYSEC-2026-2253, PYSEC-2026-2254, PYSEC-2026-2255, PYSEC-2026-2256, PYSEC-2026-2257, PYSEC-2026-2874, PYSEC-2026-3451, PYSEC-2026-3453, PYSEC-2026-3454, PYSEC-2026-3493, PYSEC-2026-3494, PYSEC-2026-3495, PYSEC-2026-3496, PYSEC-2026-457torch 1.8.1(PyPI,agent/requirements.txt): GHSA-3749-ghw9-m3mg, GHSA-47fc-vmwq-366v, GHSA-53q9-r3pm-6pq6, GHSA-5pcm-hx3q-hm94, GHSA-887c-mr87-cxwp, GHSA-c678-jfcj-6jmf, GHSA-f4hp-rmr7-r7v8, GHSA-pg7h-5qx3-wjr3, GHSA-qfhq-4f3w-5fph, GHSA-rrmf-rvhw-rf47, GHSA-vgrw-7cvw-pwgx, GHSA-x3gm-94wq-g975, PYSEC-2022-43015, PYSEC-2024-250, PYSEC-2024-251, PYSEC-2024-252, PYSEC-2024-259, PYSEC-2025-191, PYSEC-2025-198, PYSEC-2025-203, PYSEC-2025-204, PYSEC-2025-205, PYSEC-2025-206, PYSEC-2025-207, PYSEC-2025-208, PYSEC-2025-209, PYSEC-2025-41, PYSEC-2026-139, PYSEC-2026-1970, PYSEC-2026-2286Published image (trivy)
ffmpeg 7:7.1.5-0+deb13u1(no fix released)ffmpeg 7:7.1.5-0+deb13u1(no fix released)ffmpeg 7:7.1.5-0+deb13u1(no fix released)ffmpeg 7:7.1.5-0+deb13u1(no fix released)ffmpeg 7:7.1.5-0+deb13u1(no fix released)ffmpeg 7:7.1.5-0+deb13u1(no fix released)ffmpeg 7:7.1.5-0+deb13u1(no fix released)ffmpeg 7:7.1.5-0+deb13u1(no fix released)ffmpeg 7:7.1.5-0+deb13u1(no fix released)ffmpeg 7:7.1.5-0+deb13u1(no fix released)ffmpeg 7:7.1.5-0+deb13u1(no fix released)ffmpeg 7:7.1.5-0+deb13u1(no fix released)gzip 1.13-1(no fix released)libacl1 2.3.2-2+b1(no fix released)libavcodec61 7:7.1.5-0+deb13u1(no fix released)libavcodec61 7:7.1.5-0+deb13u1(no fix released)libavcodec61 7:7.1.5-0+deb13u1(no fix released)libavcodec61 7:7.1.5-0+deb13u1(no fix released)libavcodec61 7:7.1.5-0+deb13u1(no fix released)libavcodec61 7:7.1.5-0+deb13u1(no fix released)libavcodec61 7:7.1.5-0+deb13u1(no fix released)libavcodec61 7:7.1.5-0+deb13u1(no fix released)libavcodec61 7:7.1.5-0+deb13u1(no fix released)libavcodec61 7:7.1.5-0+deb13u1(no fix released)libavcodec61 7:7.1.5-0+deb13u1(no fix released)libavcodec61 7:7.1.5-0+deb13u1(no fix released)libavdevice61 7:7.1.5-0+deb13u1(no fix released)libavdevice61 7:7.1.5-0+deb13u1(no fix released)libavdevice61 7:7.1.5-0+deb13u1(no fix released)libavdevice61 7:7.1.5-0+deb13u1(no fix released)libavdevice61 7:7.1.5-0+deb13u1(no fix released)libavdevice61 7:7.1.5-0+deb13u1(no fix released)libavdevice61 7:7.1.5-0+deb13u1(no fix released)libavdevice61 7:7.1.5-0+deb13u1(no fix released)libavdevice61 7:7.1.5-0+deb13u1(no fix released)libavdevice61 7:7.1.5-0+deb13u1(no fix released)libavdevice61 7:7.1.5-0+deb13u1(no fix released)libavdevice61 7:7.1.5-0+deb13u1(no fix released)libavfilter10 7:7.1.5-0+deb13u1(no fix released)libavfilter10 7:7.1.5-0+deb13u1(no fix released)…and 146 more line(s) truncated — run the scanner locally or trigger the sweep with
only=for the full list.Coverage & limits