Security Dashboard #4

Open
opened 2026-08-09 20:58:31 -04:00 by renovate-bot · 0 comments
Collaborator

Automated weekly security sweep — last rewritten 2026-08-31 07:31 UTC (runs).

This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them with a written reason (this repo's .gitleaks.toml for secrets, an inline # nosemgrep: <rule-id> -- <reason> for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.

Secrets (gitleaks)

  • tests/core/test_crypto.py:54 — rule private-key, commit 0318f642 2026-06-16T21:17:38Z

Code findings (semgrep, curated family ruleset)

Clean — no findings.

Dependency CVEs (osv-scanner)

Skipped: no lockfiles recognized (see Coverage & limits).

Published image (trivy)

Skipped: no published image (see Coverage & limits).

Coverage & limits

  • osv-scanner found no lockfiles or manifests it recognizes — dependency-CVE coverage is unavailable for this repo, which is not the same as clean.
  • This repo publishes no container image — the image scan does not apply.
<!-- fabledsentry-security-dashboard --> _Automated weekly security sweep — last rewritten 2026-08-31 07:31 UTC ([runs](https://git.fabledsword.com/bvandeusen/CI-runner/actions))._ This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them **with a written reason** (this repo's `.gitleaks.toml` for secrets, an inline `# nosemgrep: <rule-id> -- <reason>` for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface. ## Secrets (gitleaks) - `tests/core/test_crypto.py:54` — rule `private-key`, commit `0318f642` 2026-06-16T21:17:38Z ## Code findings (semgrep, curated family ruleset) Clean — no findings. ## Dependency CVEs (osv-scanner) _Skipped: no lockfiles recognized (see Coverage & limits)._ ## Published image (trivy) _Skipped: no published image (see Coverage & limits)._ ## Coverage & limits - osv-scanner found no lockfiles or manifests it recognizes — dependency-CVE coverage is **unavailable** for this repo, which is not the same as clean. - This repo publishes no container image — the image scan does not apply.
Sign in to join this conversation.
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: bvandeusen/FabledSteward#4