Skip to content

Code Security: ecosystem dependency-CVE audit (2026-07-30) — remediation status + residuals #679

Description

@seonghobae

Centralized Code-Security governance record for a dependency-CVE sweep across the ecosystem's Python (pip-audit) and Node (npm/pnpm audit) lockfiles on 2026-07-30. Filed so findings live in the repo/Project rather than private agent memory, and so the higher-risk residuals get deliberate handling instead of an under-verified auto-bump.

Remediated this pass (fixed at base, verified, pushed)

Repo Finding Fix Verification
pg-erd-cloud (#683, 2afce4e) pydantic-settings 2.12.0 GHSA-4xgf-cpjx-pc3j; pyasn1 0.6.3 PYSEC-2026-3455/3456/3457 regen hash locks → 2.14.2 / 0.6.4 --require-hashes install hash-valid, app.main imports, mypy 68 files clean
noema (#23, 4696a13) postcss <=8.5.17 GHSA-r28c-9q8g-f849 (high) overrides^8.5.18 (8.5.25) typecheck clean, test 61 passed, security:scan 0 vulns

Open residuals (severity-classified, needing care or follow-up)

Repo Package Severity Fix path Handling
argos packages/web next-auth 5.0.0-beta.30 → beta.32 (+ @auth/core → 0.41.3) critical (GHSA-8fpg-xm3f-6cx3, GHSA-7rqj-j65f-68wh) same-beta-series prerelease bump Needs a verified auth-flow bump — beta API can shift; requires the full web test suite + auth e2e before merge. Not auto-bumped.
argos brace-expansion <1.1.16 (95 dev paths) high (ReDoS) pnpm overrides>=1.1.16 low-risk dev/transitive; can ride the same argos auth PR
pg-erd-cloud frontend (npm high, 1) high frontend lock bump candidate for the postcss/sharp override pattern
bandscope (npm high, 2) high lock/override strict 100% gates — verify quickcheck after bump
scopeweave (npm moderate, 1) moderate lock bump lower priority
codec-carver setuptools 82.0.1 PYSEC-2026-3447 (build-time) lock regen low priority; build-only
pg-erd-cloud (backend) ecdsa 0.19.2 PYSEC-2026-1325 no upstream fix published --ignore-unfixed; track for a future release

Clean (no known vulnerabilities)

contextual-orchestrator, semantic-data-portal (Python); naruon frontend (pnpm).

Note: all remediation PRs above are currently gated from merging by the org-wide opencode-review: exhausted state (the reviewer-provider credential is not yet provisioned), tracked separately at #624 — the fixes are staged and verified, awaiting pipeline recovery.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: dependenciesDependency or lockfile maintenancearea: securitySecurity boundary, hardening, or vulnerability preventionmaintenancepriority: criticalImmediate blocker, P0, urgent deadlock, or critical incidentpriority: mediumNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmenttype: maintenanceMaintenance, build, dependency, or operational upkeep

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions