Automated weekly security sweep — last rewritten 2026-10-05 07:32 UTC (runs).
This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them with a written reason (this repo's .gitleaks.toml for secrets, an inline # nosemgrep: <rule-id> -- <reason> for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.
Secrets (gitleaks)
Clean — no findings.
Code findings (semgrep, curated family ruleset)
ERROR — believed-real on this family's code (3):
alembic/versions/0015_sync_revision.py:38opt.security-rules.fabled-sql-string-interpolation — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.
alembic/versions/0015_sync_revision.py:82opt.security-rules.fabled-sql-string-interpolation — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.
alembic/versions/0015_sync_revision.py:84opt.security-rules.fabled-sql-string-interpolation — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation. WARNING — useful, precision not yet proven (1):
frontend/src/components/Icon.vue:46opt.security-rules.fabled-vue-v-html — v-html renders raw HTML into the DOM. Legitimate only when the value is server-escaped (FabledForge's Reader is). Confirm the source is escaped server-side; if it is user-supplied and unescaped this i
HIGH CVE-2026-76642 — bsdutils 1:2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-78408 — bsdutils 1:2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-78409 — bsdutils 1:2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-78410 — bsdutils 1:2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-41992 — gzip 1.13-1 → fixed in 1.13-1+deb13u1
HIGH CVE-2026-54369 — libacl1 2.3.2-2+b1 (no fix released)
HIGH CVE-2026-76642 — libblkid1 2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-78408 — libblkid1 2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-78409 — libblkid1 2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-78410 — libblkid1 2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-76642 — liblastlog2-2 2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-78408 — liblastlog2-2 2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-78409 — liblastlog2-2 2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-78410 — liblastlog2-2 2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-76642 — libmount1 2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-78408 — libmount1 2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-78409 — libmount1 2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-78410 — libmount1 2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2025-69720 — libncursesw6 6.5+20250216-2 (no fix released)
HIGH CVE-2026-103111 — libpcre2-8-0 10.46-1~deb13u1 → fixed in 10.46-1~deb13u3
HIGH CVE-2026-86145 — libpcre2-8-0 10.46-1~deb13u1 → fixed in 10.46-1~deb13u2
HIGH CVE-2026-89157 — libpcre2-8-0 10.46-1~deb13u1 → fixed in 10.46-1~deb13u2
HIGH CVE-2026-89161 — libpcre2-8-0 10.46-1~deb13u1 → fixed in 10.46-1~deb13u2
HIGH CVE-2026-76642 — libsmartcols1 2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-78408 — libsmartcols1 2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-78409 — libsmartcols1 2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-78410 — libsmartcols1 2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-11822 — libsqlite3-0 3.46.1-7+deb13u1 → fixed in 3.46.1-7+deb13u2
HIGH CVE-2026-11824 — libsqlite3-0 3.46.1-7+deb13u1 → fixed in 3.46.1-7+deb13u2
HIGH CVE-2026-14456 — libssl3t64 3.5.6-1~deb13u2 → fixed in 3.5.7-1~deb13u2
HIGH CVE-2026-75804 — libssl3t64 3.5.6-1~deb13u2 → fixed in 3.5.7-1~deb13u3
HIGH CVE-2026-84782 — libssl3t64 3.5.6-1~deb13u2 → fixed in 3.5.7-1~deb13u3
HIGH CVE-2026-16742 — libsystemd0 257.13-1~deb13u1 (no fix released)
HIGH CVE-2025-69720 — libtinfo6 6.5+20250216-2 (no fix released)
HIGH CVE-2026-16742 — libudev1 257.13-1~deb13u1 (no fix released)
HIGH CVE-2026-76642 — libuuid1 2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-78408 — libuuid1 2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-78409 — libuuid1 2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-78410 — libuuid1 2.41.5-0+deb13u1 (no fix released)
HIGH CVE-2026-76642 — login 1:4.16.0-2+really2.41.5-0+deb13u1 (no fix released) …and 28 more line(s) truncated — run the scanner locally or trigger the sweep with only= for the full list.
Coverage & limits
All four scanners ran with nothing skipped.
<!-- fabledsentry-security-dashboard -->
_Automated weekly security sweep — last rewritten 2026-10-05 07:32 UTC ([runs](https://git.fabledsword.com/bvandeusen/CI-runner/actions))._
This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them **with a written reason** (this repo's `.gitleaks.toml` for secrets, an inline `# nosemgrep: <rule-id> -- <reason>` for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.
## Secrets (gitleaks)
Clean — no findings.
## Code findings (semgrep, curated family ruleset)
**ERROR — believed-real on this family's code (3):**
- `alembic/versions/0015_sync_revision.py:38` `opt.security-rules.fabled-sql-string-interpolation` — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.
- `alembic/versions/0015_sync_revision.py:82` `opt.security-rules.fabled-sql-string-interpolation` — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.
- `alembic/versions/0015_sync_revision.py:84` `opt.security-rules.fabled-sql-string-interpolation` — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.
**WARNING — useful, precision not yet proven (1):**
- `frontend/src/components/Icon.vue:46` `opt.security-rules.fabled-vue-v-html` — v-html renders raw HTML into the DOM. Legitimate only when the value is server-escaped (FabledForge's Reader is). Confirm the source is escaped server-side; if it is user-supplied and unescaped this i
## Dependency CVEs (osv-scanner)
- `glib 0.18.5` (crates.io, `Cargo.lock`): [GHSA-wrw7-89jp-8q8g](https://osv.dev/vulnerability/GHSA-wrw7-89jp-8q8g), [RUSTSEC-2024-0429](https://osv.dev/vulnerability/RUSTSEC-2024-0429)
- `proc-macro-error 1.0.4` (crates.io, `Cargo.lock`): [RUSTSEC-2024-0370](https://osv.dev/vulnerability/RUSTSEC-2024-0370)
- `rustls 0.23.43` (crates.io, `Cargo.lock`): [RUSTSEC-2026-0285](https://osv.dev/vulnerability/RUSTSEC-2026-0285)
- `unic-char-property 0.9.0` (crates.io, `Cargo.lock`): [RUSTSEC-2025-0081](https://osv.dev/vulnerability/RUSTSEC-2025-0081)
- `unic-char-range 0.9.0` (crates.io, `Cargo.lock`): [RUSTSEC-2025-0075](https://osv.dev/vulnerability/RUSTSEC-2025-0075)
- `unic-common 0.9.0` (crates.io, `Cargo.lock`): [RUSTSEC-2025-0080](https://osv.dev/vulnerability/RUSTSEC-2025-0080)
- `unic-ucd-ident 0.9.0` (crates.io, `Cargo.lock`): [RUSTSEC-2025-0100](https://osv.dev/vulnerability/RUSTSEC-2025-0100)
- `unic-ucd-version 0.9.0` (crates.io, `Cargo.lock`): [RUSTSEC-2025-0098](https://osv.dev/vulnerability/RUSTSEC-2025-0098)
- `baseline-browser-mapping 2.10.43` (npm, `frontend/package-lock.json`): [GHSA-w5vr-8v7q-w6rv](https://osv.dev/vulnerability/GHSA-w5vr-8v7q-w6rv)
- `brace-expansion 2.1.2` (npm, `frontend/package-lock.json`): [GHSA-6j4f-fj2g-mc7p](https://osv.dev/vulnerability/GHSA-6j4f-fj2g-mc7p), [GHSA-mh99-v99m-4gvg](https://osv.dev/vulnerability/GHSA-mh99-v99m-4gvg), [GHSA-q2hr-2g5m-vwhr](https://osv.dev/vulnerability/GHSA-q2hr-2g5m-vwhr), [GHSA-qhr7-859c-m2p7](https://osv.dev/vulnerability/GHSA-qhr7-859c-m2p7), [GHSA-rgw5-rvv9-x895](https://osv.dev/vulnerability/GHSA-rgw5-rvv9-x895)
- `braces 3.0.3` (npm, `frontend/package-lock.json`): [GHSA-vfj7-8cjw-p6xm](https://osv.dev/vulnerability/GHSA-vfj7-8cjw-p6xm)
- `browserslist 4.28.6` (npm, `frontend/package-lock.json`): [GHSA-73wf-gq98-2v4g](https://osv.dev/vulnerability/GHSA-73wf-gq98-2v4g), [GHSA-c83g-rgw3-j3cx](https://osv.dev/vulnerability/GHSA-c83g-rgw3-j3cx)
- `esbuild 0.21.5` (npm, `frontend/package-lock.json`): [GHSA-67mh-4wv8-2f99](https://osv.dev/vulnerability/GHSA-67mh-4wv8-2f99)
- `nanoid 3.3.16` (npm, `frontend/package-lock.json`): [GHSA-2v37-7h3g-55p8](https://osv.dev/vulnerability/GHSA-2v37-7h3g-55p8)
- `postcss 8.5.20` (npm, `frontend/package-lock.json`): [GHSA-fxqj-rqcc-2cmp](https://osv.dev/vulnerability/GHSA-fxqj-rqcc-2cmp)
- `vite 5.4.21` (npm, `frontend/package-lock.json`): [GHSA-4w7w-66w2-5vf9](https://osv.dev/vulnerability/GHSA-4w7w-66w2-5vf9), [GHSA-fx2h-pf6j-xcff](https://osv.dev/vulnerability/GHSA-fx2h-pf6j-xcff), [GHSA-v6wh-96g9-6wx3](https://osv.dev/vulnerability/GHSA-v6wh-96g9-6wx3)
## Published image (trivy)
- **HIGH** CVE-2026-76642 — `bsdutils 1:2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-78408 — `bsdutils 1:2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-78409 — `bsdutils 1:2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-78410 — `bsdutils 1:2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-41992 — `gzip 1.13-1` → fixed in 1.13-1+deb13u1
- **HIGH** CVE-2026-54369 — `libacl1 2.3.2-2+b1` (no fix released)
- **HIGH** CVE-2026-76642 — `libblkid1 2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-78408 — `libblkid1 2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-78409 — `libblkid1 2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-78410 — `libblkid1 2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-76642 — `liblastlog2-2 2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-78408 — `liblastlog2-2 2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-78409 — `liblastlog2-2 2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-78410 — `liblastlog2-2 2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-76642 — `libmount1 2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-78408 — `libmount1 2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-78409 — `libmount1 2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-78410 — `libmount1 2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2025-69720 — `libncursesw6 6.5+20250216-2` (no fix released)
- **HIGH** CVE-2026-103111 — `libpcre2-8-0 10.46-1~deb13u1` → fixed in 10.46-1~deb13u3
- **HIGH** CVE-2026-86145 — `libpcre2-8-0 10.46-1~deb13u1` → fixed in 10.46-1~deb13u2
- **HIGH** CVE-2026-89157 — `libpcre2-8-0 10.46-1~deb13u1` → fixed in 10.46-1~deb13u2
- **HIGH** CVE-2026-89161 — `libpcre2-8-0 10.46-1~deb13u1` → fixed in 10.46-1~deb13u2
- **HIGH** CVE-2026-76642 — `libsmartcols1 2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-78408 — `libsmartcols1 2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-78409 — `libsmartcols1 2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-78410 — `libsmartcols1 2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-11822 — `libsqlite3-0 3.46.1-7+deb13u1` → fixed in 3.46.1-7+deb13u2
- **HIGH** CVE-2026-11824 — `libsqlite3-0 3.46.1-7+deb13u1` → fixed in 3.46.1-7+deb13u2
- **HIGH** CVE-2026-14456 — `libssl3t64 3.5.6-1~deb13u2` → fixed in 3.5.7-1~deb13u2
- **HIGH** CVE-2026-75804 — `libssl3t64 3.5.6-1~deb13u2` → fixed in 3.5.7-1~deb13u3
- **HIGH** CVE-2026-84782 — `libssl3t64 3.5.6-1~deb13u2` → fixed in 3.5.7-1~deb13u3
- **HIGH** CVE-2026-16742 — `libsystemd0 257.13-1~deb13u1` (no fix released)
- **HIGH** CVE-2025-69720 — `libtinfo6 6.5+20250216-2` (no fix released)
- **HIGH** CVE-2026-16742 — `libudev1 257.13-1~deb13u1` (no fix released)
- **HIGH** CVE-2026-76642 — `libuuid1 2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-78408 — `libuuid1 2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-78409 — `libuuid1 2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-78410 — `libuuid1 2.41.5-0+deb13u1` (no fix released)
- **HIGH** CVE-2026-76642 — `login 1:4.16.0-2+really2.41.5-0+deb13u1` (no fix released)
_…and 28 more line(s) truncated — run the scanner locally or trigger the sweep with `only=` for the full list._
## Coverage & limits
- All four scanners ran with nothing skipped.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Automated weekly security sweep — last rewritten 2026-10-05 07:32 UTC (runs).
This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them with a written reason (this repo's
.gitleaks.tomlfor secrets, an inline# nosemgrep: <rule-id> -- <reason>for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.Secrets (gitleaks)
Clean — no findings.
Code findings (semgrep, curated family ruleset)
ERROR — believed-real on this family's code (3):
alembic/versions/0015_sync_revision.py:38opt.security-rules.fabled-sql-string-interpolation— SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.alembic/versions/0015_sync_revision.py:82opt.security-rules.fabled-sql-string-interpolation— SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.alembic/versions/0015_sync_revision.py:84opt.security-rules.fabled-sql-string-interpolation— SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.WARNING — useful, precision not yet proven (1):
frontend/src/components/Icon.vue:46opt.security-rules.fabled-vue-v-html— v-html renders raw HTML into the DOM. Legitimate only when the value is server-escaped (FabledForge's Reader is). Confirm the source is escaped server-side; if it is user-supplied and unescaped this iDependency CVEs (osv-scanner)
glib 0.18.5(crates.io,Cargo.lock): GHSA-wrw7-89jp-8q8g, RUSTSEC-2024-0429proc-macro-error 1.0.4(crates.io,Cargo.lock): RUSTSEC-2024-0370rustls 0.23.43(crates.io,Cargo.lock): RUSTSEC-2026-0285unic-char-property 0.9.0(crates.io,Cargo.lock): RUSTSEC-2025-0081unic-char-range 0.9.0(crates.io,Cargo.lock): RUSTSEC-2025-0075unic-common 0.9.0(crates.io,Cargo.lock): RUSTSEC-2025-0080unic-ucd-ident 0.9.0(crates.io,Cargo.lock): RUSTSEC-2025-0100unic-ucd-version 0.9.0(crates.io,Cargo.lock): RUSTSEC-2025-0098baseline-browser-mapping 2.10.43(npm,frontend/package-lock.json): GHSA-w5vr-8v7q-w6rvbrace-expansion 2.1.2(npm,frontend/package-lock.json): GHSA-6j4f-fj2g-mc7p, GHSA-mh99-v99m-4gvg, GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7, GHSA-rgw5-rvv9-x895braces 3.0.3(npm,frontend/package-lock.json): GHSA-vfj7-8cjw-p6xmbrowserslist 4.28.6(npm,frontend/package-lock.json): GHSA-73wf-gq98-2v4g, GHSA-c83g-rgw3-j3cxesbuild 0.21.5(npm,frontend/package-lock.json): GHSA-67mh-4wv8-2f99nanoid 3.3.16(npm,frontend/package-lock.json): GHSA-2v37-7h3g-55p8postcss 8.5.20(npm,frontend/package-lock.json): GHSA-fxqj-rqcc-2cmpvite 5.4.21(npm,frontend/package-lock.json): GHSA-4w7w-66w2-5vf9, GHSA-fx2h-pf6j-xcff, GHSA-v6wh-96g9-6wx3Published image (trivy)
bsdutils 1:2.41.5-0+deb13u1(no fix released)bsdutils 1:2.41.5-0+deb13u1(no fix released)bsdutils 1:2.41.5-0+deb13u1(no fix released)bsdutils 1:2.41.5-0+deb13u1(no fix released)gzip 1.13-1→ fixed in 1.13-1+deb13u1libacl1 2.3.2-2+b1(no fix released)libblkid1 2.41.5-0+deb13u1(no fix released)libblkid1 2.41.5-0+deb13u1(no fix released)libblkid1 2.41.5-0+deb13u1(no fix released)libblkid1 2.41.5-0+deb13u1(no fix released)liblastlog2-2 2.41.5-0+deb13u1(no fix released)liblastlog2-2 2.41.5-0+deb13u1(no fix released)liblastlog2-2 2.41.5-0+deb13u1(no fix released)liblastlog2-2 2.41.5-0+deb13u1(no fix released)libmount1 2.41.5-0+deb13u1(no fix released)libmount1 2.41.5-0+deb13u1(no fix released)libmount1 2.41.5-0+deb13u1(no fix released)libmount1 2.41.5-0+deb13u1(no fix released)libncursesw6 6.5+20250216-2(no fix released)libpcre2-8-0 10.46-1~deb13u1→ fixed in 10.46-1~deb13u3libpcre2-8-0 10.46-1~deb13u1→ fixed in 10.46-1~deb13u2libpcre2-8-0 10.46-1~deb13u1→ fixed in 10.46-1~deb13u2libpcre2-8-0 10.46-1~deb13u1→ fixed in 10.46-1~deb13u2libsmartcols1 2.41.5-0+deb13u1(no fix released)libsmartcols1 2.41.5-0+deb13u1(no fix released)libsmartcols1 2.41.5-0+deb13u1(no fix released)libsmartcols1 2.41.5-0+deb13u1(no fix released)libsqlite3-0 3.46.1-7+deb13u1→ fixed in 3.46.1-7+deb13u2libsqlite3-0 3.46.1-7+deb13u1→ fixed in 3.46.1-7+deb13u2libssl3t64 3.5.6-1~deb13u2→ fixed in 3.5.7-1~deb13u2libssl3t64 3.5.6-1~deb13u2→ fixed in 3.5.7-1~deb13u3libssl3t64 3.5.6-1~deb13u2→ fixed in 3.5.7-1~deb13u3libsystemd0 257.13-1~deb13u1(no fix released)libtinfo6 6.5+20250216-2(no fix released)libudev1 257.13-1~deb13u1(no fix released)libuuid1 2.41.5-0+deb13u1(no fix released)libuuid1 2.41.5-0+deb13u1(no fix released)libuuid1 2.41.5-0+deb13u1(no fix released)libuuid1 2.41.5-0+deb13u1(no fix released)login 1:4.16.0-2+really2.41.5-0+deb13u1(no fix released)…and 28 more line(s) truncated — run the scanner locally or trigger the sweep with
only=for the full list.Coverage & limits