Security Dashboard #1

Open
opened 2026-08-09 20:59:35 -04:00 by renovate-bot · 0 comments

Automated weekly security sweep — last rewritten 2026-10-05 07:32 UTC (runs).

This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them with a written reason (this repo's .gitleaks.toml for secrets, an inline # nosemgrep: <rule-id> -- <reason> for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.

Secrets (gitleaks)

Clean — no findings.

Code findings (semgrep, curated family ruleset)

ERROR — believed-real on this family's code (3):

  • alembic/versions/0015_sync_revision.py:38 opt.security-rules.fabled-sql-string-interpolation — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.
  • alembic/versions/0015_sync_revision.py:82 opt.security-rules.fabled-sql-string-interpolation — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.
  • alembic/versions/0015_sync_revision.py:84 opt.security-rules.fabled-sql-string-interpolation — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.
    WARNING — useful, precision not yet proven (1):
  • frontend/src/components/Icon.vue:46 opt.security-rules.fabled-vue-v-html — v-html renders raw HTML into the DOM. Legitimate only when the value is server-escaped (FabledForge's Reader is). Confirm the source is escaped server-side; if it is user-supplied and unescaped this i

Dependency CVEs (osv-scanner)

Published image (trivy)

  • HIGH CVE-2026-76642 — bsdutils 1:2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-78408 — bsdutils 1:2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-78409 — bsdutils 1:2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-78410 — bsdutils 1:2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-41992 — gzip 1.13-1 → fixed in 1.13-1+deb13u1
  • HIGH CVE-2026-54369 — libacl1 2.3.2-2+b1 (no fix released)
  • HIGH CVE-2026-76642 — libblkid1 2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-78408 — libblkid1 2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-78409 — libblkid1 2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-78410 — libblkid1 2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-76642 — liblastlog2-2 2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-78408 — liblastlog2-2 2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-78409 — liblastlog2-2 2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-78410 — liblastlog2-2 2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-76642 — libmount1 2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-78408 — libmount1 2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-78409 — libmount1 2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-78410 — libmount1 2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2025-69720 — libncursesw6 6.5+20250216-2 (no fix released)
  • HIGH CVE-2026-103111 — libpcre2-8-0 10.46-1~deb13u1 → fixed in 10.46-1~deb13u3
  • HIGH CVE-2026-86145 — libpcre2-8-0 10.46-1~deb13u1 → fixed in 10.46-1~deb13u2
  • HIGH CVE-2026-89157 — libpcre2-8-0 10.46-1~deb13u1 → fixed in 10.46-1~deb13u2
  • HIGH CVE-2026-89161 — libpcre2-8-0 10.46-1~deb13u1 → fixed in 10.46-1~deb13u2
  • HIGH CVE-2026-76642 — libsmartcols1 2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-78408 — libsmartcols1 2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-78409 — libsmartcols1 2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-78410 — libsmartcols1 2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-11822 — libsqlite3-0 3.46.1-7+deb13u1 → fixed in 3.46.1-7+deb13u2
  • HIGH CVE-2026-11824 — libsqlite3-0 3.46.1-7+deb13u1 → fixed in 3.46.1-7+deb13u2
  • HIGH CVE-2026-14456 — libssl3t64 3.5.6-1~deb13u2 → fixed in 3.5.7-1~deb13u2
  • HIGH CVE-2026-75804 — libssl3t64 3.5.6-1~deb13u2 → fixed in 3.5.7-1~deb13u3
  • HIGH CVE-2026-84782 — libssl3t64 3.5.6-1~deb13u2 → fixed in 3.5.7-1~deb13u3
  • HIGH CVE-2026-16742 — libsystemd0 257.13-1~deb13u1 (no fix released)
  • HIGH CVE-2025-69720 — libtinfo6 6.5+20250216-2 (no fix released)
  • HIGH CVE-2026-16742 — libudev1 257.13-1~deb13u1 (no fix released)
  • HIGH CVE-2026-76642 — libuuid1 2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-78408 — libuuid1 2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-78409 — libuuid1 2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-78410 — libuuid1 2.41.5-0+deb13u1 (no fix released)
  • HIGH CVE-2026-76642 — login 1:4.16.0-2+really2.41.5-0+deb13u1 (no fix released)
    …and 28 more line(s) truncated — run the scanner locally or trigger the sweep with only= for the full list.

Coverage & limits

  • All four scanners ran with nothing skipped.
<!-- fabledsentry-security-dashboard --> _Automated weekly security sweep — last rewritten 2026-10-05 07:32 UTC ([runs](https://git.fabledsword.com/bvandeusen/CI-runner/actions))._ This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them **with a written reason** (this repo's `.gitleaks.toml` for secrets, an inline `# nosemgrep: <rule-id> -- <reason>` for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface. ## Secrets (gitleaks) Clean — no findings. ## Code findings (semgrep, curated family ruleset) **ERROR — believed-real on this family's code (3):** - `alembic/versions/0015_sync_revision.py:38` `opt.security-rules.fabled-sql-string-interpolation` — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation. - `alembic/versions/0015_sync_revision.py:82` `opt.security-rules.fabled-sql-string-interpolation` — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation. - `alembic/versions/0015_sync_revision.py:84` `opt.security-rules.fabled-sql-string-interpolation` — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation. **WARNING — useful, precision not yet proven (1):** - `frontend/src/components/Icon.vue:46` `opt.security-rules.fabled-vue-v-html` — v-html renders raw HTML into the DOM. Legitimate only when the value is server-escaped (FabledForge's Reader is). Confirm the source is escaped server-side; if it is user-supplied and unescaped this i ## Dependency CVEs (osv-scanner) - `glib 0.18.5` (crates.io, `Cargo.lock`): [GHSA-wrw7-89jp-8q8g](https://osv.dev/vulnerability/GHSA-wrw7-89jp-8q8g), [RUSTSEC-2024-0429](https://osv.dev/vulnerability/RUSTSEC-2024-0429) - `proc-macro-error 1.0.4` (crates.io, `Cargo.lock`): [RUSTSEC-2024-0370](https://osv.dev/vulnerability/RUSTSEC-2024-0370) - `rustls 0.23.43` (crates.io, `Cargo.lock`): [RUSTSEC-2026-0285](https://osv.dev/vulnerability/RUSTSEC-2026-0285) - `unic-char-property 0.9.0` (crates.io, `Cargo.lock`): [RUSTSEC-2025-0081](https://osv.dev/vulnerability/RUSTSEC-2025-0081) - `unic-char-range 0.9.0` (crates.io, `Cargo.lock`): [RUSTSEC-2025-0075](https://osv.dev/vulnerability/RUSTSEC-2025-0075) - `unic-common 0.9.0` (crates.io, `Cargo.lock`): [RUSTSEC-2025-0080](https://osv.dev/vulnerability/RUSTSEC-2025-0080) - `unic-ucd-ident 0.9.0` (crates.io, `Cargo.lock`): [RUSTSEC-2025-0100](https://osv.dev/vulnerability/RUSTSEC-2025-0100) - `unic-ucd-version 0.9.0` (crates.io, `Cargo.lock`): [RUSTSEC-2025-0098](https://osv.dev/vulnerability/RUSTSEC-2025-0098) - `baseline-browser-mapping 2.10.43` (npm, `frontend/package-lock.json`): [GHSA-w5vr-8v7q-w6rv](https://osv.dev/vulnerability/GHSA-w5vr-8v7q-w6rv) - `brace-expansion 2.1.2` (npm, `frontend/package-lock.json`): [GHSA-6j4f-fj2g-mc7p](https://osv.dev/vulnerability/GHSA-6j4f-fj2g-mc7p), [GHSA-mh99-v99m-4gvg](https://osv.dev/vulnerability/GHSA-mh99-v99m-4gvg), [GHSA-q2hr-2g5m-vwhr](https://osv.dev/vulnerability/GHSA-q2hr-2g5m-vwhr), [GHSA-qhr7-859c-m2p7](https://osv.dev/vulnerability/GHSA-qhr7-859c-m2p7), [GHSA-rgw5-rvv9-x895](https://osv.dev/vulnerability/GHSA-rgw5-rvv9-x895) - `braces 3.0.3` (npm, `frontend/package-lock.json`): [GHSA-vfj7-8cjw-p6xm](https://osv.dev/vulnerability/GHSA-vfj7-8cjw-p6xm) - `browserslist 4.28.6` (npm, `frontend/package-lock.json`): [GHSA-73wf-gq98-2v4g](https://osv.dev/vulnerability/GHSA-73wf-gq98-2v4g), [GHSA-c83g-rgw3-j3cx](https://osv.dev/vulnerability/GHSA-c83g-rgw3-j3cx) - `esbuild 0.21.5` (npm, `frontend/package-lock.json`): [GHSA-67mh-4wv8-2f99](https://osv.dev/vulnerability/GHSA-67mh-4wv8-2f99) - `nanoid 3.3.16` (npm, `frontend/package-lock.json`): [GHSA-2v37-7h3g-55p8](https://osv.dev/vulnerability/GHSA-2v37-7h3g-55p8) - `postcss 8.5.20` (npm, `frontend/package-lock.json`): [GHSA-fxqj-rqcc-2cmp](https://osv.dev/vulnerability/GHSA-fxqj-rqcc-2cmp) - `vite 5.4.21` (npm, `frontend/package-lock.json`): [GHSA-4w7w-66w2-5vf9](https://osv.dev/vulnerability/GHSA-4w7w-66w2-5vf9), [GHSA-fx2h-pf6j-xcff](https://osv.dev/vulnerability/GHSA-fx2h-pf6j-xcff), [GHSA-v6wh-96g9-6wx3](https://osv.dev/vulnerability/GHSA-v6wh-96g9-6wx3) ## Published image (trivy) - **HIGH** CVE-2026-76642 — `bsdutils 1:2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-78408 — `bsdutils 1:2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-78409 — `bsdutils 1:2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-78410 — `bsdutils 1:2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-41992 — `gzip 1.13-1` → fixed in 1.13-1+deb13u1 - **HIGH** CVE-2026-54369 — `libacl1 2.3.2-2+b1` (no fix released) - **HIGH** CVE-2026-76642 — `libblkid1 2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-78408 — `libblkid1 2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-78409 — `libblkid1 2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-78410 — `libblkid1 2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-76642 — `liblastlog2-2 2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-78408 — `liblastlog2-2 2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-78409 — `liblastlog2-2 2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-78410 — `liblastlog2-2 2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-76642 — `libmount1 2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-78408 — `libmount1 2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-78409 — `libmount1 2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-78410 — `libmount1 2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2025-69720 — `libncursesw6 6.5+20250216-2` (no fix released) - **HIGH** CVE-2026-103111 — `libpcre2-8-0 10.46-1~deb13u1` → fixed in 10.46-1~deb13u3 - **HIGH** CVE-2026-86145 — `libpcre2-8-0 10.46-1~deb13u1` → fixed in 10.46-1~deb13u2 - **HIGH** CVE-2026-89157 — `libpcre2-8-0 10.46-1~deb13u1` → fixed in 10.46-1~deb13u2 - **HIGH** CVE-2026-89161 — `libpcre2-8-0 10.46-1~deb13u1` → fixed in 10.46-1~deb13u2 - **HIGH** CVE-2026-76642 — `libsmartcols1 2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-78408 — `libsmartcols1 2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-78409 — `libsmartcols1 2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-78410 — `libsmartcols1 2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-11822 — `libsqlite3-0 3.46.1-7+deb13u1` → fixed in 3.46.1-7+deb13u2 - **HIGH** CVE-2026-11824 — `libsqlite3-0 3.46.1-7+deb13u1` → fixed in 3.46.1-7+deb13u2 - **HIGH** CVE-2026-14456 — `libssl3t64 3.5.6-1~deb13u2` → fixed in 3.5.7-1~deb13u2 - **HIGH** CVE-2026-75804 — `libssl3t64 3.5.6-1~deb13u2` → fixed in 3.5.7-1~deb13u3 - **HIGH** CVE-2026-84782 — `libssl3t64 3.5.6-1~deb13u2` → fixed in 3.5.7-1~deb13u3 - **HIGH** CVE-2026-16742 — `libsystemd0 257.13-1~deb13u1` (no fix released) - **HIGH** CVE-2025-69720 — `libtinfo6 6.5+20250216-2` (no fix released) - **HIGH** CVE-2026-16742 — `libudev1 257.13-1~deb13u1` (no fix released) - **HIGH** CVE-2026-76642 — `libuuid1 2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-78408 — `libuuid1 2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-78409 — `libuuid1 2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-78410 — `libuuid1 2.41.5-0+deb13u1` (no fix released) - **HIGH** CVE-2026-76642 — `login 1:4.16.0-2+really2.41.5-0+deb13u1` (no fix released) _…and 28 more line(s) truncated — run the scanner locally or trigger the sweep with `only=` for the full list._ ## Coverage & limits - All four scanners ran with nothing skipped.
Sign in to join this conversation.
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: bvandeusen/inkwell#1