Automated weekly security sweep — last rewritten 2026-08-31 07:31 UTC (runs).
This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them with a written reason (this repo's .gitleaks.toml for secrets, an inline # nosemgrep: <rule-id> -- <reason> for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.
Secrets (gitleaks)
Clean — no findings.
Code findings (semgrep, curated family ruleset)
ERROR — believed-real on this family's code (3):
alembic/versions/0015_sync_revision.py:38opt.security-rules.fabled-sql-string-interpolation — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.
alembic/versions/0015_sync_revision.py:82opt.security-rules.fabled-sql-string-interpolation — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.
alembic/versions/0015_sync_revision.py:84opt.security-rules.fabled-sql-string-interpolation — SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation. WARNING — useful, precision not yet proven (1):
frontend/src/components/Icon.vue:46opt.security-rules.fabled-vue-v-html — v-html renders raw HTML into the DOM. Legitimate only when the value is server-escaped (FabledForge's Reader is). Confirm the source is escaped server-side; if it is user-supplied and unescaped this i
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Automated weekly security sweep — last rewritten 2026-08-31 07:31 UTC (runs).
This issue is maintained like the Renovate Dependency Dashboard: every sweep run rewrites it in place. Don't edit findings here — fix them, or allowlist them with a written reason (this repo's
.gitleaks.tomlfor secrets, an inline# nosemgrep: <rule-id> -- <reason>for code findings). There is no per-push security lane; this dashboard and the on-demand deep review are where security findings surface.Secrets (gitleaks)
Clean — no findings.
Code findings (semgrep, curated family ruleset)
ERROR — believed-real on this family's code (3):
alembic/versions/0015_sync_revision.py:38opt.security-rules.fabled-sql-string-interpolation— SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.alembic/versions/0015_sync_revision.py:82opt.security-rules.fabled-sql-string-interpolation— SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.alembic/versions/0015_sync_revision.py:84opt.security-rules.fabled-sql-string-interpolation— SQL built by string interpolation. This family is ORM-first; raw SQL assembled from an f-string bypasses parameter binding. Use bound parameters — text("... :id"), {"id": value} — not interpolation.WARNING — useful, precision not yet proven (1):
frontend/src/components/Icon.vue:46opt.security-rules.fabled-vue-v-html— v-html renders raw HTML into the DOM. Legitimate only when the value is server-escaped (FabledForge's Reader is). Confirm the source is escaped server-side; if it is user-supplied and unescaped this iDependency CVEs (osv-scanner)
atk 0.18.2(crates.io,Cargo.lock): RUSTSEC-2024-0413atk-sys 0.18.2(crates.io,Cargo.lock): RUSTSEC-2024-0416gdk 0.18.2(crates.io,Cargo.lock): RUSTSEC-2024-0412gdk-sys 0.18.2(crates.io,Cargo.lock): RUSTSEC-2024-0418gdkwayland-sys 0.18.2(crates.io,Cargo.lock): RUSTSEC-2024-0411gdkx11 0.18.2(crates.io,Cargo.lock): RUSTSEC-2024-0417gdkx11-sys 0.18.2(crates.io,Cargo.lock): RUSTSEC-2024-0414glib 0.18.5(crates.io,Cargo.lock): GHSA-wrw7-89jp-8q8g, RUSTSEC-2024-0429gtk 0.18.2(crates.io,Cargo.lock): RUSTSEC-2024-0415gtk-sys 0.18.2(crates.io,Cargo.lock): RUSTSEC-2024-0420gtk3-macros 0.18.2(crates.io,Cargo.lock): RUSTSEC-2024-0419proc-macro-error 1.0.4(crates.io,Cargo.lock): RUSTSEC-2024-0370unic-char-property 0.9.0(crates.io,Cargo.lock): RUSTSEC-2025-0081unic-char-range 0.9.0(crates.io,Cargo.lock): RUSTSEC-2025-0075unic-common 0.9.0(crates.io,Cargo.lock): RUSTSEC-2025-0080unic-ucd-ident 0.9.0(crates.io,Cargo.lock): RUSTSEC-2025-0100unic-ucd-version 0.9.0(crates.io,Cargo.lock): RUSTSEC-2025-0098brace-expansion 2.1.2(npm,frontend/package-lock.json): GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895esbuild 0.21.5(npm,frontend/package-lock.json): GHSA-67mh-4wv8-2f99nanoid 3.3.16(npm,frontend/package-lock.json): GHSA-2v37-7h3g-55p8postcss 8.5.20(npm,frontend/package-lock.json): GHSA-fxqj-rqcc-2cmpvite 5.4.21(npm,frontend/package-lock.json): GHSA-4w7w-66w2-5vf9, GHSA-fx2h-pf6j-xcff, GHSA-v6wh-96g9-6wx3Published image (trivy)
gzip 1.13-1(no fix released)libacl1 2.3.2-2+b1(no fix released)libncursesw6 6.5+20250216-2(no fix released)libsqlite3-0 3.46.1-7+deb13u1(no fix released)libsqlite3-0 3.46.1-7+deb13u1(no fix released)libssl3t64 3.5.6-1~deb13u2→ fixed in 3.5.7-1~deb13u2libtinfo6 6.5+20250216-2(no fix released)ncurses-base 6.5+20250216-2(no fix released)ncurses-bin 6.5+20250216-2(no fix released)openssl 3.5.6-1~deb13u2→ fixed in 3.5.7-1~deb13u2openssl-provider-legacy 3.5.6-1~deb13u2→ fixed in 3.5.7-1~deb13u2perl-base 5.40.1-6(no fix released)perl-base 5.40.1-6(no fix released)perl-base 5.40.1-6(no fix released)perl-base 5.40.1-6(no fix released)perl-base 5.40.1-6(no fix released)perl-base 5.40.1-6(no fix released)perl-base 5.40.1-6(no fix released)perl-base 5.40.1-6(no fix released)Totals for
git.fabledsword.com/bvandeusen/thoughtsync:latest: 3 CRITICAL, 16 HIGH, 64 MEDIUM, 76 LOW, 7 UNKNOWN. Only CRITICAL/HIGH are itemized above.Coverage & limits