Skip to content

fix(security): resolve the open Dependabot and CodeQL alerts - #494

Merged
agjs merged 3 commits into
mainfrom
fix/security-alerts
Oct 9, 2026
Merged

agjs merged 3 commits into
mainfrom
fix/security-alerts

Conversation

@agjs

@agjs agjs commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Summary

Closes every open security alert on main.

Test plan

  • osv-scanner clean for api, docs and site with no handlebars ignores; scripts/ci/bun-audit.sh clean for api
  • apps/api: bun run check, bun run test (1289 pass); email templates compile with 4.7.10
  • apps/docs build:ci, apps/site validate, agent:check (98 pass), agent:quality
  • Valkey started with --entrypoint sh and -e VALKEY_PASSWORD in a throwaway container: valkey-cli with REDISCLI_AUTH gets PONG, and without it gets NOAUTH
  • CI's agent verification job runs the full isolated sandbox

agjs added 3 commits October 9, 2026 08:58
4.7.10 is the only release that fixes two critical JavaScript-injection
advisories. It is exempted from the 7-day quarantine, like form-data was,
and the three osv ignores are removed.
The override already installed 0.35.5, but Dependabot reads the direct
dependency and kept GHSA-wq5f-xc86-pv6w open.
The isolated runtime passed the Postgres and Valkey passwords as docker
arguments. They now travel in the Docker client's environment through
-e NAME, so they never reach a process list or an error message.
Resolves CodeQL js/clear-text-logging.
@agjs
agjs merged commit 9e2d543 into main Oct 9, 2026
35 checks passed
@agjs
agjs deleted the fix/security-alerts branch October 9, 2026 07:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant