Automated weekly security sweep — last rewritten 2026-08-31 07:31 UTC (runs).
This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them with a written reason (this repo's .gitleaks.toml for secrets, an inline # nosemgrep: <rule-id> -- <reason> for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.
Secrets (gitleaks)
Clean — no findings.
Code findings (semgrep, curated family ruleset)
Clean — no findings.
Dependency CVEs (osv-scanner)
Clean — no findings.
Published image (trivy)
HIGH CVE-2026-53612 — bsdutils 1:2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53613 — bsdutils 1:2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53614 — bsdutils 1:2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53615 — bsdutils 1:2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-41992 — gzip 1.13-1 (no fix released)
HIGH CVE-2026-54369 — libacl1 2.3.2-2+b1 (no fix released)
HIGH CVE-2026-53612 — libblkid1 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53613 — libblkid1 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53614 — libblkid1 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53615 — libblkid1 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53612 — liblastlog2-2 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53613 — liblastlog2-2 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53614 — liblastlog2-2 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53615 — liblastlog2-2 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53612 — libmount1 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53613 — libmount1 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53614 — libmount1 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53615 — libmount1 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2025-69720 — libncursesw6 6.5+20250216-2 (no fix released)
HIGH CVE-2026-53612 — libsmartcols1 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53613 — libsmartcols1 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53614 — libsmartcols1 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53615 — libsmartcols1 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-11822 — libsqlite3-0 3.46.1-7+deb13u1 (no fix released)
HIGH CVE-2026-11824 — libsqlite3-0 3.46.1-7+deb13u1 (no fix released)
HIGH CVE-2026-14456 — libssl3t64 3.5.6-1~deb13u2 → fixed in 3.5.7-1~deb13u2
HIGH CVE-2025-69720 — libtinfo6 6.5+20250216-2 (no fix released)
HIGH CVE-2026-53612 — libuuid1 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53613 — libuuid1 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53614 — libuuid1 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53615 — libuuid1 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53612 — login 1:4.16.0-2+really2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53613 — login 1:4.16.0-2+really2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53614 — login 1:4.16.0-2+really2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53615 — login 1:4.16.0-2+really2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53612 — mount 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53613 — mount 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53614 — mount 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2026-53615 — mount 2.41-5 → fixed in 2.41.5-0+deb13u1
HIGH CVE-2025-69720 — ncurses-base 6.5+20250216-2 (no fix released) …and 16 more line(s) truncated — run the scanner locally or trigger the sweep with only= for the full list.
Coverage & limits
All four scanners ran with nothing skipped.
<!-- fabledsentry-security-dashboard -->
_Automated weekly security sweep — last rewritten 2026-08-31 07:31 UTC ([runs](https://git.fabledsword.com/bvandeusen/CI-runner/actions))._
This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them **with a written reason** (this repo's `.gitleaks.toml` for secrets, an inline `# nosemgrep: <rule-id> -- <reason>` for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.
## Secrets (gitleaks)
Clean — no findings.
## Code findings (semgrep, curated family ruleset)
Clean — no findings.
## Dependency CVEs (osv-scanner)
Clean — no findings.
## Published image (trivy)
- **HIGH** CVE-2026-53612 — `bsdutils 1:2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53613 — `bsdutils 1:2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53614 — `bsdutils 1:2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53615 — `bsdutils 1:2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-41992 — `gzip 1.13-1` (no fix released)
- **HIGH** CVE-2026-54369 — `libacl1 2.3.2-2+b1` (no fix released)
- **HIGH** CVE-2026-53612 — `libblkid1 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53613 — `libblkid1 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53614 — `libblkid1 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53615 — `libblkid1 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53612 — `liblastlog2-2 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53613 — `liblastlog2-2 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53614 — `liblastlog2-2 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53615 — `liblastlog2-2 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53612 — `libmount1 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53613 — `libmount1 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53614 — `libmount1 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53615 — `libmount1 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2025-69720 — `libncursesw6 6.5+20250216-2` (no fix released)
- **HIGH** CVE-2026-53612 — `libsmartcols1 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53613 — `libsmartcols1 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53614 — `libsmartcols1 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53615 — `libsmartcols1 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-11822 — `libsqlite3-0 3.46.1-7+deb13u1` (no fix released)
- **HIGH** CVE-2026-11824 — `libsqlite3-0 3.46.1-7+deb13u1` (no fix released)
- **HIGH** CVE-2026-14456 — `libssl3t64 3.5.6-1~deb13u2` → fixed in 3.5.7-1~deb13u2
- **HIGH** CVE-2025-69720 — `libtinfo6 6.5+20250216-2` (no fix released)
- **HIGH** CVE-2026-53612 — `libuuid1 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53613 — `libuuid1 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53614 — `libuuid1 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53615 — `libuuid1 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53612 — `login 1:4.16.0-2+really2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53613 — `login 1:4.16.0-2+really2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53614 — `login 1:4.16.0-2+really2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53615 — `login 1:4.16.0-2+really2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53612 — `mount 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53613 — `mount 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53614 — `mount 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2026-53615 — `mount 2.41-5` → fixed in 2.41.5-0+deb13u1
- **HIGH** CVE-2025-69720 — `ncurses-base 6.5+20250216-2` (no fix released)
_…and 16 more line(s) truncated — run the scanner locally or trigger the sweep with `only=` for the full list._
## Coverage & limits
- All four scanners ran with nothing skipped.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Automated weekly security sweep — last rewritten 2026-08-31 07:31 UTC (runs).
This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them with a written reason (this repo's
.gitleaks.tomlfor secrets, an inline# nosemgrep: <rule-id> -- <reason>for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.Secrets (gitleaks)
Clean — no findings.
Code findings (semgrep, curated family ruleset)
Clean — no findings.
Dependency CVEs (osv-scanner)
Clean — no findings.
Published image (trivy)
bsdutils 1:2.41-5→ fixed in 2.41.5-0+deb13u1bsdutils 1:2.41-5→ fixed in 2.41.5-0+deb13u1bsdutils 1:2.41-5→ fixed in 2.41.5-0+deb13u1bsdutils 1:2.41-5→ fixed in 2.41.5-0+deb13u1gzip 1.13-1(no fix released)libacl1 2.3.2-2+b1(no fix released)libblkid1 2.41-5→ fixed in 2.41.5-0+deb13u1libblkid1 2.41-5→ fixed in 2.41.5-0+deb13u1libblkid1 2.41-5→ fixed in 2.41.5-0+deb13u1libblkid1 2.41-5→ fixed in 2.41.5-0+deb13u1liblastlog2-2 2.41-5→ fixed in 2.41.5-0+deb13u1liblastlog2-2 2.41-5→ fixed in 2.41.5-0+deb13u1liblastlog2-2 2.41-5→ fixed in 2.41.5-0+deb13u1liblastlog2-2 2.41-5→ fixed in 2.41.5-0+deb13u1libmount1 2.41-5→ fixed in 2.41.5-0+deb13u1libmount1 2.41-5→ fixed in 2.41.5-0+deb13u1libmount1 2.41-5→ fixed in 2.41.5-0+deb13u1libmount1 2.41-5→ fixed in 2.41.5-0+deb13u1libncursesw6 6.5+20250216-2(no fix released)libsmartcols1 2.41-5→ fixed in 2.41.5-0+deb13u1libsmartcols1 2.41-5→ fixed in 2.41.5-0+deb13u1libsmartcols1 2.41-5→ fixed in 2.41.5-0+deb13u1libsmartcols1 2.41-5→ fixed in 2.41.5-0+deb13u1libsqlite3-0 3.46.1-7+deb13u1(no fix released)libsqlite3-0 3.46.1-7+deb13u1(no fix released)libssl3t64 3.5.6-1~deb13u2→ fixed in 3.5.7-1~deb13u2libtinfo6 6.5+20250216-2(no fix released)libuuid1 2.41-5→ fixed in 2.41.5-0+deb13u1libuuid1 2.41-5→ fixed in 2.41.5-0+deb13u1libuuid1 2.41-5→ fixed in 2.41.5-0+deb13u1libuuid1 2.41-5→ fixed in 2.41.5-0+deb13u1login 1:4.16.0-2+really2.41-5→ fixed in 2.41.5-0+deb13u1login 1:4.16.0-2+really2.41-5→ fixed in 2.41.5-0+deb13u1login 1:4.16.0-2+really2.41-5→ fixed in 2.41.5-0+deb13u1login 1:4.16.0-2+really2.41-5→ fixed in 2.41.5-0+deb13u1mount 2.41-5→ fixed in 2.41.5-0+deb13u1mount 2.41-5→ fixed in 2.41.5-0+deb13u1mount 2.41-5→ fixed in 2.41.5-0+deb13u1mount 2.41-5→ fixed in 2.41.5-0+deb13u1ncurses-base 6.5+20250216-2(no fix released)…and 16 more line(s) truncated — run the scanner locally or trigger the sweep with
only=for the full list.Coverage & limits