Automated weekly security sweep — last rewritten 2026-08-31 07:31 UTC (runs).
This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them with a written reason (this repo's .gitleaks.toml for secrets, an inline # nosemgrep: <rule-id> -- <reason> for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.
HIGH CVE-2026-53613 — bsdutils 1:2.38.1-5+deb12u3 (no fix released)
HIGH CVE-2026-53615 — bsdutils 1:2.38.1-5+deb12u3 (no fix released)
HIGH CVE-2026-58049 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-64830 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-64831 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-64832 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-64834 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-64835 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-66036 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-66039 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-66040 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-70628 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-70632 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-8461 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-41992 — gzip 1.12-1 (no fix released)
HIGH CVE-2026-54369 — libacl1 2.3.1-3 (no fix released)
CRITICAL CVE-2023-6879 — libaom3 3.6.0-1+deb12u2 (no fix released)
HIGH CVE-2023-39616 — libaom3 3.6.0-1+deb12u2 (no fix released)
HIGH CVE-2026-56208 — libaom3 3.6.0-1+deb12u2 (no fix released)
HIGH CVE-2026-56209 — libaom3 3.6.0-1+deb12u2 (no fix released)
HIGH CVE-2026-56210 — libaom3 3.6.0-1+deb12u2 (no fix released)
HIGH CVE-2026-56211 — libaom3 3.6.0-1+deb12u2 (no fix released)
HIGH CVE-2026-58049 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-64830 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-64831 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-64832 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-64834 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-64835 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-66036 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-66039 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-66040 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-70628 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-70632 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-8461 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-58049 — libavdevice59 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-64830 — libavdevice59 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-64831 — libavdevice59 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-64832 — libavdevice59 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-64834 — libavdevice59 7:5.1.9-0+deb12u1 (no fix released)
HIGH CVE-2026-64835 — libavdevice59 7:5.1.9-0+deb12u1 (no fix released) …and 155 more line(s) truncated — run the scanner locally or trigger the sweep with only= for the full list.
Coverage & limits
All four scanners ran with nothing skipped.
<!-- fabledsentry-security-dashboard -->
_Automated weekly security sweep — last rewritten 2026-08-31 07:31 UTC ([runs](https://git.fabledsword.com/bvandeusen/CI-runner/actions))._
This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them **with a written reason** (this repo's `.gitleaks.toml` for secrets, an inline `# nosemgrep: <rule-id> -- <reason>` for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.
## Secrets (gitleaks)
- `internal/api/auth_register_test.go:99` — rule `generic-api-key`, commit `a4493989` 2026-05-07T15:56:19Z
## Code findings (semgrep, curated family ruleset)
Clean — no findings.
## Dependency CVEs (osv-scanner)
- `github.com/go-chi/chi/v5 5.2.5` (Go, `go.mod`): [GO-2026-5774](https://osv.dev/vulnerability/GO-2026-5774), [GO-2026-5775](https://osv.dev/vulnerability/GO-2026-5775), [GO-2026-5777](https://osv.dev/vulnerability/GO-2026-5777)
- `golang.org/x/crypto 0.51.0` (Go, `go.mod`): [GHSA-45gg-vh54-h5m9](https://osv.dev/vulnerability/GHSA-45gg-vh54-h5m9), [GHSA-5cgq-3rg8-m6cv](https://osv.dev/vulnerability/GHSA-5cgq-3rg8-m6cv), [GHSA-78mq-xcr3-xm33](https://osv.dev/vulnerability/GHSA-78mq-xcr3-xm33), [GHSA-89gr-r52h-f8rx](https://osv.dev/vulnerability/GHSA-89gr-r52h-f8rx), [GHSA-9m57-25v3-79x9](https://osv.dev/vulnerability/GHSA-9m57-25v3-79x9), [GHSA-f5wc-c3c7-36mc](https://osv.dev/vulnerability/GHSA-f5wc-c3c7-36mc), [GHSA-jppx-rxg9-jmrx](https://osv.dev/vulnerability/GHSA-jppx-rxg9-jmrx), [GHSA-q4h4-gmj2-qvw2](https://osv.dev/vulnerability/GHSA-q4h4-gmj2-qvw2), [GHSA-qpw4-5x99-6vjp](https://osv.dev/vulnerability/GHSA-qpw4-5x99-6vjp), [GHSA-rm3j-f69w-wqmq](https://osv.dev/vulnerability/GHSA-rm3j-f69w-wqmq), [GHSA-vgwf-h737-ff37](https://osv.dev/vulnerability/GHSA-vgwf-h737-ff37), [GHSA-w879-237q-wc7r](https://osv.dev/vulnerability/GHSA-w879-237q-wc7r), [GHSA-x527-x647-q7gg](https://osv.dev/vulnerability/GHSA-x527-x647-q7gg), [GO-2026-5005](https://osv.dev/vulnerability/GO-2026-5005), [GO-2026-5006](https://osv.dev/vulnerability/GO-2026-5006), [GO-2026-5013](https://osv.dev/vulnerability/GO-2026-5013), [GO-2026-5014](https://osv.dev/vulnerability/GO-2026-5014), [GO-2026-5015](https://osv.dev/vulnerability/GO-2026-5015), [GO-2026-5016](https://osv.dev/vulnerability/GO-2026-5016), [GO-2026-5017](https://osv.dev/vulnerability/GO-2026-5017), [GO-2026-5018](https://osv.dev/vulnerability/GO-2026-5018), [GO-2026-5019](https://osv.dev/vulnerability/GO-2026-5019), [GO-2026-5020](https://osv.dev/vulnerability/GO-2026-5020), [GO-2026-5021](https://osv.dev/vulnerability/GO-2026-5021), [GO-2026-5023](https://osv.dev/vulnerability/GO-2026-5023), [GO-2026-5033](https://osv.dev/vulnerability/GO-2026-5033), [GO-2026-5932](https://osv.dev/vulnerability/GO-2026-5932), [GO-2026-6303](https://osv.dev/vulnerability/GO-2026-6303)
- `golang.org/x/text 0.37.0` (Go, `go.mod`): [GO-2026-5970](https://osv.dev/vulnerability/GO-2026-5970)
- `sharp 0.34.5` (npm, `tools/package-lock.json`): [GHSA-f88m-g3jw-g9cj](https://osv.dev/vulnerability/GHSA-f88m-g3jw-g9cj)
- `@sveltejs/kit 2.57.1` (npm, `web/package-lock.json`): [GHSA-29g2-3rmr-qm68](https://osv.dev/vulnerability/GHSA-29g2-3rmr-qm68), [GHSA-866w-xmhq-wj7x](https://osv.dev/vulnerability/GHSA-866w-xmhq-wj7x), [GHSA-hgv7-v322-mmgr](https://osv.dev/vulnerability/GHSA-hgv7-v322-mmgr), [GHSA-wqjv-9729-c5q2](https://osv.dev/vulnerability/GHSA-wqjv-9729-c5q2)
- `cookie 0.6.0` (npm, `web/package-lock.json`): [GHSA-pxg6-pf52-xh8x](https://osv.dev/vulnerability/GHSA-pxg6-pf52-xh8x)
- `devalue 5.7.1` (npm, `web/package-lock.json`): [GHSA-77vg-94rm-hx3p](https://osv.dev/vulnerability/GHSA-77vg-94rm-hx3p)
- `esbuild 0.21.5` (npm, `web/package-lock.json`): [GHSA-67mh-4wv8-2f99](https://osv.dev/vulnerability/GHSA-67mh-4wv8-2f99)
- `form-data 4.0.5` (npm, `web/package-lock.json`): [GHSA-hmw2-7cc7-3qxx](https://osv.dev/vulnerability/GHSA-hmw2-7cc7-3qxx)
- `nanoid 3.3.12` (npm, `web/package-lock.json`): [GHSA-28wg-ghj8-5hjv](https://osv.dev/vulnerability/GHSA-28wg-ghj8-5hjv), [GHSA-2v37-7h3g-55p8](https://osv.dev/vulnerability/GHSA-2v37-7h3g-55p8)
- `postcss 8.5.15` (npm, `web/package-lock.json`): [GHSA-fxqj-rqcc-2cmp](https://osv.dev/vulnerability/GHSA-fxqj-rqcc-2cmp), [GHSA-r28c-9q8g-f849](https://osv.dev/vulnerability/GHSA-r28c-9q8g-f849)
- `svelte 5.55.4` (npm, `web/package-lock.json`): [GHSA-9rmh-mm8f-r9h6](https://osv.dev/vulnerability/GHSA-9rmh-mm8f-r9h6), [GHSA-f3cj-j4f6-wq85](https://osv.dev/vulnerability/GHSA-f3cj-j4f6-wq85), [GHSA-pr6f-5x2q-rwfp](https://osv.dev/vulnerability/GHSA-pr6f-5x2q-rwfp), [GHSA-rcqx-6q8c-2c42](https://osv.dev/vulnerability/GHSA-rcqx-6q8c-2c42)
- `vite 5.4.21` (npm, `web/package-lock.json`): [GHSA-4w7w-66w2-5vf9](https://osv.dev/vulnerability/GHSA-4w7w-66w2-5vf9), [GHSA-fx2h-pf6j-xcff](https://osv.dev/vulnerability/GHSA-fx2h-pf6j-xcff), [GHSA-v6wh-96g9-6wx3](https://osv.dev/vulnerability/GHSA-v6wh-96g9-6wx3)
- `vitest 2.1.9` (npm, `web/package-lock.json`): [GHSA-5xrq-8626-4rwp](https://osv.dev/vulnerability/GHSA-5xrq-8626-4rwp)
- `ws 8.20.0` (npm, `web/package-lock.json`): [GHSA-58qx-3vcg-4xpx](https://osv.dev/vulnerability/GHSA-58qx-3vcg-4xpx), [GHSA-96hv-2xvq-fx4p](https://osv.dev/vulnerability/GHSA-96hv-2xvq-fx4p)
## Published image (trivy)
- **HIGH** CVE-2026-53613 — `bsdutils 1:2.38.1-5+deb12u3` (no fix released)
- **HIGH** CVE-2026-53615 — `bsdutils 1:2.38.1-5+deb12u3` (no fix released)
- **HIGH** CVE-2026-58049 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-64830 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-64831 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-64832 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-64834 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-64835 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-66036 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-66039 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-66040 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-70628 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-70632 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-8461 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-41992 — `gzip 1.12-1` (no fix released)
- **HIGH** CVE-2026-54369 — `libacl1 2.3.1-3` (no fix released)
- **CRITICAL** CVE-2023-6879 — `libaom3 3.6.0-1+deb12u2` (no fix released)
- **HIGH** CVE-2023-39616 — `libaom3 3.6.0-1+deb12u2` (no fix released)
- **HIGH** CVE-2026-56208 — `libaom3 3.6.0-1+deb12u2` (no fix released)
- **HIGH** CVE-2026-56209 — `libaom3 3.6.0-1+deb12u2` (no fix released)
- **HIGH** CVE-2026-56210 — `libaom3 3.6.0-1+deb12u2` (no fix released)
- **HIGH** CVE-2026-56211 — `libaom3 3.6.0-1+deb12u2` (no fix released)
- **HIGH** CVE-2026-58049 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-64830 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-64831 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-64832 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-64834 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-64835 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-66036 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-66039 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-66040 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-70628 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-70632 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-8461 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-58049 — `libavdevice59 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-64830 — `libavdevice59 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-64831 — `libavdevice59 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-64832 — `libavdevice59 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-64834 — `libavdevice59 7:5.1.9-0+deb12u1` (no fix released)
- **HIGH** CVE-2026-64835 — `libavdevice59 7:5.1.9-0+deb12u1` (no fix released)
_…and 155 more line(s) truncated — run the scanner locally or trigger the sweep with `only=` for the full list._
## Coverage & limits
- All four scanners ran with nothing skipped.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Automated weekly security sweep — last rewritten 2026-08-31 07:31 UTC (runs).
This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them with a written reason (this repo's
.gitleaks.tomlfor secrets, an inline# nosemgrep: <rule-id> -- <reason>for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.Secrets (gitleaks)
internal/api/auth_register_test.go:99— rulegeneric-api-key, commita44939892026-05-07T15:56:19ZCode findings (semgrep, curated family ruleset)
Clean — no findings.
Dependency CVEs (osv-scanner)
github.com/go-chi/chi/v5 5.2.5(Go,go.mod): GO-2026-5774, GO-2026-5775, GO-2026-5777golang.org/x/crypto 0.51.0(Go,go.mod): GHSA-45gg-vh54-h5m9, GHSA-5cgq-3rg8-m6cv, GHSA-78mq-xcr3-xm33, GHSA-89gr-r52h-f8rx, GHSA-9m57-25v3-79x9, GHSA-f5wc-c3c7-36mc, GHSA-jppx-rxg9-jmrx, GHSA-q4h4-gmj2-qvw2, GHSA-qpw4-5x99-6vjp, GHSA-rm3j-f69w-wqmq, GHSA-vgwf-h737-ff37, GHSA-w879-237q-wc7r, GHSA-x527-x647-q7gg, GO-2026-5005, GO-2026-5006, GO-2026-5013, GO-2026-5014, GO-2026-5015, GO-2026-5016, GO-2026-5017, GO-2026-5018, GO-2026-5019, GO-2026-5020, GO-2026-5021, GO-2026-5023, GO-2026-5033, GO-2026-5932, GO-2026-6303golang.org/x/text 0.37.0(Go,go.mod): GO-2026-5970sharp 0.34.5(npm,tools/package-lock.json): GHSA-f88m-g3jw-g9cj@sveltejs/kit 2.57.1(npm,web/package-lock.json): GHSA-29g2-3rmr-qm68, GHSA-866w-xmhq-wj7x, GHSA-hgv7-v322-mmgr, GHSA-wqjv-9729-c5q2cookie 0.6.0(npm,web/package-lock.json): GHSA-pxg6-pf52-xh8xdevalue 5.7.1(npm,web/package-lock.json): GHSA-77vg-94rm-hx3pesbuild 0.21.5(npm,web/package-lock.json): GHSA-67mh-4wv8-2f99form-data 4.0.5(npm,web/package-lock.json): GHSA-hmw2-7cc7-3qxxnanoid 3.3.12(npm,web/package-lock.json): GHSA-28wg-ghj8-5hjv, GHSA-2v37-7h3g-55p8postcss 8.5.15(npm,web/package-lock.json): GHSA-fxqj-rqcc-2cmp, GHSA-r28c-9q8g-f849svelte 5.55.4(npm,web/package-lock.json): GHSA-9rmh-mm8f-r9h6, GHSA-f3cj-j4f6-wq85, GHSA-pr6f-5x2q-rwfp, GHSA-rcqx-6q8c-2c42vite 5.4.21(npm,web/package-lock.json): GHSA-4w7w-66w2-5vf9, GHSA-fx2h-pf6j-xcff, GHSA-v6wh-96g9-6wx3vitest 2.1.9(npm,web/package-lock.json): GHSA-5xrq-8626-4rwpws 8.20.0(npm,web/package-lock.json): GHSA-58qx-3vcg-4xpx, GHSA-96hv-2xvq-fx4pPublished image (trivy)
bsdutils 1:2.38.1-5+deb12u3(no fix released)bsdutils 1:2.38.1-5+deb12u3(no fix released)ffmpeg 7:5.1.9-0+deb12u1(no fix released)ffmpeg 7:5.1.9-0+deb12u1(no fix released)ffmpeg 7:5.1.9-0+deb12u1(no fix released)ffmpeg 7:5.1.9-0+deb12u1(no fix released)ffmpeg 7:5.1.9-0+deb12u1(no fix released)ffmpeg 7:5.1.9-0+deb12u1(no fix released)ffmpeg 7:5.1.9-0+deb12u1(no fix released)ffmpeg 7:5.1.9-0+deb12u1(no fix released)ffmpeg 7:5.1.9-0+deb12u1(no fix released)ffmpeg 7:5.1.9-0+deb12u1(no fix released)ffmpeg 7:5.1.9-0+deb12u1(no fix released)ffmpeg 7:5.1.9-0+deb12u1(no fix released)gzip 1.12-1(no fix released)libacl1 2.3.1-3(no fix released)libaom3 3.6.0-1+deb12u2(no fix released)libaom3 3.6.0-1+deb12u2(no fix released)libaom3 3.6.0-1+deb12u2(no fix released)libaom3 3.6.0-1+deb12u2(no fix released)libaom3 3.6.0-1+deb12u2(no fix released)libaom3 3.6.0-1+deb12u2(no fix released)libavcodec59 7:5.1.9-0+deb12u1(no fix released)libavcodec59 7:5.1.9-0+deb12u1(no fix released)libavcodec59 7:5.1.9-0+deb12u1(no fix released)libavcodec59 7:5.1.9-0+deb12u1(no fix released)libavcodec59 7:5.1.9-0+deb12u1(no fix released)libavcodec59 7:5.1.9-0+deb12u1(no fix released)libavcodec59 7:5.1.9-0+deb12u1(no fix released)libavcodec59 7:5.1.9-0+deb12u1(no fix released)libavcodec59 7:5.1.9-0+deb12u1(no fix released)libavcodec59 7:5.1.9-0+deb12u1(no fix released)libavcodec59 7:5.1.9-0+deb12u1(no fix released)libavcodec59 7:5.1.9-0+deb12u1(no fix released)libavdevice59 7:5.1.9-0+deb12u1(no fix released)libavdevice59 7:5.1.9-0+deb12u1(no fix released)libavdevice59 7:5.1.9-0+deb12u1(no fix released)libavdevice59 7:5.1.9-0+deb12u1(no fix released)libavdevice59 7:5.1.9-0+deb12u1(no fix released)libavdevice59 7:5.1.9-0+deb12u1(no fix released)…and 155 more line(s) truncated — run the scanner locally or trigger the sweep with
only=for the full list.Coverage & limits