Security Dashboard #125

Open
opened 2026-08-09 20:59:10 -04:00 by renovate-bot · 0 comments
Collaborator

Automated weekly security sweep — last rewritten 2026-08-31 07:31 UTC (runs).

This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them with a written reason (this repo's .gitleaks.toml for secrets, an inline # nosemgrep: <rule-id> -- <reason> for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.

Secrets (gitleaks)

  • internal/api/auth_register_test.go:99 — rule generic-api-key, commit a4493989 2026-05-07T15:56:19Z

Code findings (semgrep, curated family ruleset)

Clean — no findings.

Dependency CVEs (osv-scanner)

Published image (trivy)

  • HIGH CVE-2026-53613 — bsdutils 1:2.38.1-5+deb12u3 (no fix released)
  • HIGH CVE-2026-53615 — bsdutils 1:2.38.1-5+deb12u3 (no fix released)
  • HIGH CVE-2026-58049 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-64830 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-64831 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-64832 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-64834 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-64835 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-66036 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-66039 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-66040 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-70628 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-70632 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-8461 — ffmpeg 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-41992 — gzip 1.12-1 (no fix released)
  • HIGH CVE-2026-54369 — libacl1 2.3.1-3 (no fix released)
  • CRITICAL CVE-2023-6879 — libaom3 3.6.0-1+deb12u2 (no fix released)
  • HIGH CVE-2023-39616 — libaom3 3.6.0-1+deb12u2 (no fix released)
  • HIGH CVE-2026-56208 — libaom3 3.6.0-1+deb12u2 (no fix released)
  • HIGH CVE-2026-56209 — libaom3 3.6.0-1+deb12u2 (no fix released)
  • HIGH CVE-2026-56210 — libaom3 3.6.0-1+deb12u2 (no fix released)
  • HIGH CVE-2026-56211 — libaom3 3.6.0-1+deb12u2 (no fix released)
  • HIGH CVE-2026-58049 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-64830 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-64831 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-64832 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-64834 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-64835 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-66036 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-66039 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-66040 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-70628 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-70632 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-8461 — libavcodec59 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-58049 — libavdevice59 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-64830 — libavdevice59 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-64831 — libavdevice59 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-64832 — libavdevice59 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-64834 — libavdevice59 7:5.1.9-0+deb12u1 (no fix released)
  • HIGH CVE-2026-64835 — libavdevice59 7:5.1.9-0+deb12u1 (no fix released)
    …and 155 more line(s) truncated — run the scanner locally or trigger the sweep with only= for the full list.

Coverage & limits

  • All four scanners ran with nothing skipped.
<!-- fabledsentry-security-dashboard --> _Automated weekly security sweep — last rewritten 2026-08-31 07:31 UTC ([runs](https://git.fabledsword.com/bvandeusen/CI-runner/actions))._ This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them **with a written reason** (this repo's `.gitleaks.toml` for secrets, an inline `# nosemgrep: <rule-id> -- <reason>` for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface. ## Secrets (gitleaks) - `internal/api/auth_register_test.go:99` — rule `generic-api-key`, commit `a4493989` 2026-05-07T15:56:19Z ## Code findings (semgrep, curated family ruleset) Clean — no findings. ## Dependency CVEs (osv-scanner) - `github.com/go-chi/chi/v5 5.2.5` (Go, `go.mod`): [GO-2026-5774](https://osv.dev/vulnerability/GO-2026-5774), [GO-2026-5775](https://osv.dev/vulnerability/GO-2026-5775), [GO-2026-5777](https://osv.dev/vulnerability/GO-2026-5777) - `golang.org/x/crypto 0.51.0` (Go, `go.mod`): [GHSA-45gg-vh54-h5m9](https://osv.dev/vulnerability/GHSA-45gg-vh54-h5m9), [GHSA-5cgq-3rg8-m6cv](https://osv.dev/vulnerability/GHSA-5cgq-3rg8-m6cv), [GHSA-78mq-xcr3-xm33](https://osv.dev/vulnerability/GHSA-78mq-xcr3-xm33), [GHSA-89gr-r52h-f8rx](https://osv.dev/vulnerability/GHSA-89gr-r52h-f8rx), [GHSA-9m57-25v3-79x9](https://osv.dev/vulnerability/GHSA-9m57-25v3-79x9), [GHSA-f5wc-c3c7-36mc](https://osv.dev/vulnerability/GHSA-f5wc-c3c7-36mc), [GHSA-jppx-rxg9-jmrx](https://osv.dev/vulnerability/GHSA-jppx-rxg9-jmrx), [GHSA-q4h4-gmj2-qvw2](https://osv.dev/vulnerability/GHSA-q4h4-gmj2-qvw2), [GHSA-qpw4-5x99-6vjp](https://osv.dev/vulnerability/GHSA-qpw4-5x99-6vjp), [GHSA-rm3j-f69w-wqmq](https://osv.dev/vulnerability/GHSA-rm3j-f69w-wqmq), [GHSA-vgwf-h737-ff37](https://osv.dev/vulnerability/GHSA-vgwf-h737-ff37), [GHSA-w879-237q-wc7r](https://osv.dev/vulnerability/GHSA-w879-237q-wc7r), [GHSA-x527-x647-q7gg](https://osv.dev/vulnerability/GHSA-x527-x647-q7gg), [GO-2026-5005](https://osv.dev/vulnerability/GO-2026-5005), [GO-2026-5006](https://osv.dev/vulnerability/GO-2026-5006), [GO-2026-5013](https://osv.dev/vulnerability/GO-2026-5013), [GO-2026-5014](https://osv.dev/vulnerability/GO-2026-5014), [GO-2026-5015](https://osv.dev/vulnerability/GO-2026-5015), [GO-2026-5016](https://osv.dev/vulnerability/GO-2026-5016), [GO-2026-5017](https://osv.dev/vulnerability/GO-2026-5017), [GO-2026-5018](https://osv.dev/vulnerability/GO-2026-5018), [GO-2026-5019](https://osv.dev/vulnerability/GO-2026-5019), [GO-2026-5020](https://osv.dev/vulnerability/GO-2026-5020), [GO-2026-5021](https://osv.dev/vulnerability/GO-2026-5021), [GO-2026-5023](https://osv.dev/vulnerability/GO-2026-5023), [GO-2026-5033](https://osv.dev/vulnerability/GO-2026-5033), [GO-2026-5932](https://osv.dev/vulnerability/GO-2026-5932), [GO-2026-6303](https://osv.dev/vulnerability/GO-2026-6303) - `golang.org/x/text 0.37.0` (Go, `go.mod`): [GO-2026-5970](https://osv.dev/vulnerability/GO-2026-5970) - `sharp 0.34.5` (npm, `tools/package-lock.json`): [GHSA-f88m-g3jw-g9cj](https://osv.dev/vulnerability/GHSA-f88m-g3jw-g9cj) - `@sveltejs/kit 2.57.1` (npm, `web/package-lock.json`): [GHSA-29g2-3rmr-qm68](https://osv.dev/vulnerability/GHSA-29g2-3rmr-qm68), [GHSA-866w-xmhq-wj7x](https://osv.dev/vulnerability/GHSA-866w-xmhq-wj7x), [GHSA-hgv7-v322-mmgr](https://osv.dev/vulnerability/GHSA-hgv7-v322-mmgr), [GHSA-wqjv-9729-c5q2](https://osv.dev/vulnerability/GHSA-wqjv-9729-c5q2) - `cookie 0.6.0` (npm, `web/package-lock.json`): [GHSA-pxg6-pf52-xh8x](https://osv.dev/vulnerability/GHSA-pxg6-pf52-xh8x) - `devalue 5.7.1` (npm, `web/package-lock.json`): [GHSA-77vg-94rm-hx3p](https://osv.dev/vulnerability/GHSA-77vg-94rm-hx3p) - `esbuild 0.21.5` (npm, `web/package-lock.json`): [GHSA-67mh-4wv8-2f99](https://osv.dev/vulnerability/GHSA-67mh-4wv8-2f99) - `form-data 4.0.5` (npm, `web/package-lock.json`): [GHSA-hmw2-7cc7-3qxx](https://osv.dev/vulnerability/GHSA-hmw2-7cc7-3qxx) - `nanoid 3.3.12` (npm, `web/package-lock.json`): [GHSA-28wg-ghj8-5hjv](https://osv.dev/vulnerability/GHSA-28wg-ghj8-5hjv), [GHSA-2v37-7h3g-55p8](https://osv.dev/vulnerability/GHSA-2v37-7h3g-55p8) - `postcss 8.5.15` (npm, `web/package-lock.json`): [GHSA-fxqj-rqcc-2cmp](https://osv.dev/vulnerability/GHSA-fxqj-rqcc-2cmp), [GHSA-r28c-9q8g-f849](https://osv.dev/vulnerability/GHSA-r28c-9q8g-f849) - `svelte 5.55.4` (npm, `web/package-lock.json`): [GHSA-9rmh-mm8f-r9h6](https://osv.dev/vulnerability/GHSA-9rmh-mm8f-r9h6), [GHSA-f3cj-j4f6-wq85](https://osv.dev/vulnerability/GHSA-f3cj-j4f6-wq85), [GHSA-pr6f-5x2q-rwfp](https://osv.dev/vulnerability/GHSA-pr6f-5x2q-rwfp), [GHSA-rcqx-6q8c-2c42](https://osv.dev/vulnerability/GHSA-rcqx-6q8c-2c42) - `vite 5.4.21` (npm, `web/package-lock.json`): [GHSA-4w7w-66w2-5vf9](https://osv.dev/vulnerability/GHSA-4w7w-66w2-5vf9), [GHSA-fx2h-pf6j-xcff](https://osv.dev/vulnerability/GHSA-fx2h-pf6j-xcff), [GHSA-v6wh-96g9-6wx3](https://osv.dev/vulnerability/GHSA-v6wh-96g9-6wx3) - `vitest 2.1.9` (npm, `web/package-lock.json`): [GHSA-5xrq-8626-4rwp](https://osv.dev/vulnerability/GHSA-5xrq-8626-4rwp) - `ws 8.20.0` (npm, `web/package-lock.json`): [GHSA-58qx-3vcg-4xpx](https://osv.dev/vulnerability/GHSA-58qx-3vcg-4xpx), [GHSA-96hv-2xvq-fx4p](https://osv.dev/vulnerability/GHSA-96hv-2xvq-fx4p) ## Published image (trivy) - **HIGH** CVE-2026-53613 — `bsdutils 1:2.38.1-5+deb12u3` (no fix released) - **HIGH** CVE-2026-53615 — `bsdutils 1:2.38.1-5+deb12u3` (no fix released) - **HIGH** CVE-2026-58049 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-64830 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-64831 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-64832 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-64834 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-64835 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-66036 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-66039 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-66040 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-70628 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-70632 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-8461 — `ffmpeg 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-41992 — `gzip 1.12-1` (no fix released) - **HIGH** CVE-2026-54369 — `libacl1 2.3.1-3` (no fix released) - **CRITICAL** CVE-2023-6879 — `libaom3 3.6.0-1+deb12u2` (no fix released) - **HIGH** CVE-2023-39616 — `libaom3 3.6.0-1+deb12u2` (no fix released) - **HIGH** CVE-2026-56208 — `libaom3 3.6.0-1+deb12u2` (no fix released) - **HIGH** CVE-2026-56209 — `libaom3 3.6.0-1+deb12u2` (no fix released) - **HIGH** CVE-2026-56210 — `libaom3 3.6.0-1+deb12u2` (no fix released) - **HIGH** CVE-2026-56211 — `libaom3 3.6.0-1+deb12u2` (no fix released) - **HIGH** CVE-2026-58049 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-64830 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-64831 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-64832 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-64834 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-64835 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-66036 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-66039 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-66040 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-70628 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-70632 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-8461 — `libavcodec59 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-58049 — `libavdevice59 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-64830 — `libavdevice59 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-64831 — `libavdevice59 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-64832 — `libavdevice59 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-64834 — `libavdevice59 7:5.1.9-0+deb12u1` (no fix released) - **HIGH** CVE-2026-64835 — `libavdevice59 7:5.1.9-0+deb12u1` (no fix released) _…and 155 more line(s) truncated — run the scanner locally or trigger the sweep with `only=` for the full list._ ## Coverage & limits - All four scanners ran with nothing skipped.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: bvandeusen/minstrel#125