Automated weekly security sweep — last rewritten 2026-08-31 07:31 UTC (runs).
This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them with a written reason (this repo's .gitleaks.toml for secrets, an inline # nosemgrep: <rule-id> -- <reason> for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.
Skipped: no lockfiles recognized (see Coverage & limits).
Published image (trivy)
Skipped: no published image (see Coverage & limits).
Coverage & limits
osv-scanner found no lockfiles or manifests it recognizes — dependency-CVE coverage is unavailable for this repo, which is not the same as clean.
This repo publishes no container image — the image scan does not apply.
<!-- fabledsentry-security-dashboard -->
_Automated weekly security sweep — last rewritten 2026-08-31 07:31 UTC ([runs](https://git.fabledsword.com/bvandeusen/CI-runner/actions))._
This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them **with a written reason** (this repo's `.gitleaks.toml` for secrets, an inline `# nosemgrep: <rule-id> -- <reason>` for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.
## Secrets (gitleaks)
- `tests/core/test_crypto.py:54` — rule `private-key`, commit `0318f642` 2026-06-16T21:17:38Z
## Code findings (semgrep, curated family ruleset)
Clean — no findings.
## Dependency CVEs (osv-scanner)
_Skipped: no lockfiles recognized (see Coverage & limits)._
## Published image (trivy)
_Skipped: no published image (see Coverage & limits)._
## Coverage & limits
- osv-scanner found no lockfiles or manifests it recognizes — dependency-CVE coverage is **unavailable** for this repo, which is not the same as clean.
- This repo publishes no container image — the image scan does not apply.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Automated weekly security sweep — last rewritten 2026-08-31 07:31 UTC (runs).
This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them with a written reason (this repo's
.gitleaks.tomlfor secrets, an inline# nosemgrep: <rule-id> -- <reason>for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.Secrets (gitleaks)
tests/core/test_crypto.py:54— ruleprivate-key, commit0318f6422026-06-16T21:17:38ZCode findings (semgrep, curated family ruleset)
Clean — no findings.
Dependency CVEs (osv-scanner)
Skipped: no lockfiles recognized (see Coverage & limits).
Published image (trivy)
Skipped: no published image (see Coverage & limits).
Coverage & limits