Skip to content

docs(audit): dependabot alert audit — 127 total, 64 open, grouped by severity#11

Draft
Fearvox wants to merge 1 commit into
mainfrom
sleep-iter-6-dependabot-audit
Draft

docs(audit): dependabot alert audit — 127 total, 64 open, grouped by severity#11
Fearvox wants to merge 1 commit into
mainfrom
sleep-iter-6-dependabot-audit

Conversation

@Fearvox
Copy link
Copy Markdown
Owner

@Fearvox Fearvox commented May 13, 2026

Summary

  • Full audit of 127 Dependabot alerts (64 open, 63 fixed) via GitHub API
  • 64 unique vulnerability families across 2 ecosystems (126 pip, 1 npm)
  • 2 critical: langchain-core serialization injection + NLTK zip slip
  • Hotspot analysis: aiohttp (15), nltk (7), langchain* (8), urllib3 (4), python-multipart (3)
  • 4-tier recommendation: immediate (2 critical), high-priority (24 high), medium (23 medium), no-action (63 fixed evermemos)

Test plan

  • Alert data from live GitHub API (gh api /repos/Fearvox/EverOS/dependabot/alerts)
  • Severity counts match GitHub UI (2 critical, 24 high, 23 moderate, 15 low)
  • All 64 open alerts individually enumerated by severity group

🤖 Generated with Claude Code

…severity

64 unique vulnerability families across EverCore uv.lock (63 pip) and
game-of-throne-demo (1 npm). 2 critical (langchain-core serialization,
NLTK zip slip), 24 high, 23 medium, 15 low. Hotspot analysis identifies
aiohttp (15), nltk (7), langchain* (8), urllib3 (4) as top clusters.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@Fearvox Fearvox added pr-mirror Long-lived mirror of an upstream PR for Linear/Slack tracking tracking Issue tracks a long-lived workflow labels May 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr-mirror Long-lived mirror of an upstream PR for Linear/Slack tracking tracking Issue tracks a long-lived workflow

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant