Security Dashboard #3

Open
opened 2026-08-09 20:59:32 -04:00 by renovate-bot · 0 comments

Automated weekly security sweep — last rewritten 2026-08-31 07:31 UTC (runs).

This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them with a written reason (this repo's .gitleaks.toml for secrets, an inline # nosemgrep: <rule-id> -- <reason> for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.

Secrets (gitleaks)

Clean — no findings.

Code findings (semgrep, curated family ruleset)

Clean — no findings.

Dependency CVEs (osv-scanner)

Clean — no findings.

Published image (trivy)

  • HIGH CVE-2026-53612 — bsdutils 1:2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53613 — bsdutils 1:2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53614 — bsdutils 1:2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53615 — bsdutils 1:2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-41992 — gzip 1.13-1 (no fix released)
  • HIGH CVE-2026-54369 — libacl1 2.3.2-2+b1 (no fix released)
  • HIGH CVE-2026-53612 — libblkid1 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53613 — libblkid1 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53614 — libblkid1 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53615 — libblkid1 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53612 — liblastlog2-2 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53613 — liblastlog2-2 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53614 — liblastlog2-2 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53615 — liblastlog2-2 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53612 — libmount1 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53613 — libmount1 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53614 — libmount1 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53615 — libmount1 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2025-69720 — libncursesw6 6.5+20250216-2 (no fix released)
  • HIGH CVE-2026-53612 — libsmartcols1 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53613 — libsmartcols1 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53614 — libsmartcols1 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53615 — libsmartcols1 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-11822 — libsqlite3-0 3.46.1-7+deb13u1 (no fix released)
  • HIGH CVE-2026-11824 — libsqlite3-0 3.46.1-7+deb13u1 (no fix released)
  • HIGH CVE-2026-14456 — libssl3t64 3.5.6-1~deb13u2 → fixed in 3.5.7-1~deb13u2
  • HIGH CVE-2025-69720 — libtinfo6 6.5+20250216-2 (no fix released)
  • HIGH CVE-2026-53612 — libuuid1 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53613 — libuuid1 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53614 — libuuid1 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53615 — libuuid1 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53612 — login 1:4.16.0-2+really2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53613 — login 1:4.16.0-2+really2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53614 — login 1:4.16.0-2+really2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53615 — login 1:4.16.0-2+really2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53612 — mount 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53613 — mount 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53614 — mount 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2026-53615 — mount 2.41-5 → fixed in 2.41.5-0+deb13u1
  • HIGH CVE-2025-69720 — ncurses-base 6.5+20250216-2 (no fix released)
    …and 16 more line(s) truncated — run the scanner locally or trigger the sweep with only= for the full list.

Coverage & limits

  • All four scanners ran with nothing skipped.
<!-- fabledsentry-security-dashboard --> _Automated weekly security sweep — last rewritten 2026-08-31 07:31 UTC ([runs](https://git.fabledsword.com/bvandeusen/CI-runner/actions))._ This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them **with a written reason** (this repo's `.gitleaks.toml` for secrets, an inline `# nosemgrep: <rule-id> -- <reason>` for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface. ## Secrets (gitleaks) Clean — no findings. ## Code findings (semgrep, curated family ruleset) Clean — no findings. ## Dependency CVEs (osv-scanner) Clean — no findings. ## Published image (trivy) - **HIGH** CVE-2026-53612 — `bsdutils 1:2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53613 — `bsdutils 1:2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53614 — `bsdutils 1:2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53615 — `bsdutils 1:2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-41992 — `gzip 1.13-1` (no fix released) - **HIGH** CVE-2026-54369 — `libacl1 2.3.2-2+b1` (no fix released) - **HIGH** CVE-2026-53612 — `libblkid1 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53613 — `libblkid1 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53614 — `libblkid1 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53615 — `libblkid1 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53612 — `liblastlog2-2 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53613 — `liblastlog2-2 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53614 — `liblastlog2-2 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53615 — `liblastlog2-2 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53612 — `libmount1 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53613 — `libmount1 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53614 — `libmount1 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53615 — `libmount1 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2025-69720 — `libncursesw6 6.5+20250216-2` (no fix released) - **HIGH** CVE-2026-53612 — `libsmartcols1 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53613 — `libsmartcols1 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53614 — `libsmartcols1 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53615 — `libsmartcols1 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-11822 — `libsqlite3-0 3.46.1-7+deb13u1` (no fix released) - **HIGH** CVE-2026-11824 — `libsqlite3-0 3.46.1-7+deb13u1` (no fix released) - **HIGH** CVE-2026-14456 — `libssl3t64 3.5.6-1~deb13u2` → fixed in 3.5.7-1~deb13u2 - **HIGH** CVE-2025-69720 — `libtinfo6 6.5+20250216-2` (no fix released) - **HIGH** CVE-2026-53612 — `libuuid1 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53613 — `libuuid1 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53614 — `libuuid1 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53615 — `libuuid1 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53612 — `login 1:4.16.0-2+really2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53613 — `login 1:4.16.0-2+really2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53614 — `login 1:4.16.0-2+really2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53615 — `login 1:4.16.0-2+really2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53612 — `mount 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53613 — `mount 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53614 — `mount 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2026-53615 — `mount 2.41-5` → fixed in 2.41.5-0+deb13u1 - **HIGH** CVE-2025-69720 — `ncurses-base 6.5+20250216-2` (no fix released) _…and 16 more line(s) truncated — run the scanner locally or trigger the sweep with `only=` for the full list._ ## Coverage & limits - All four scanners ran with nothing skipped.
Sign in to join this conversation.
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: bvandeusen/StashHandler#3