Nightly security & dependency sweep for 2026-09-11.
| Alert |
Classification |
Action |
Evidence |
| CodeQL open alerts (all) |
unread — could not be listed |
none |
GITHUB_CODEWHALE_SECURITY_PAT not provisioned; default credential got HTTP 403 Resource not accessible by integration on GET /repos/Hmbown/CodeWhale/code-scanning/alerts. Nothing was dismissed. |
| Dependabot #129 sharp (root) |
true positive, fix available |
bumped 0.35.3 → 0.35.4 |
#6057 |
| Dependabot #136 sharp (web) |
true positive, fix available |
bumped 0.35.3 → 0.35.4 |
#6057 |
| Dependabot #132 sharp (telemetry-ingest) |
true positive, fix available |
override added, 0.35.2 → 0.35.4 |
#6057 |
| Dependabot #135 js-yaml (web) |
true positive, fix available |
4.3.1 → 4.3.2 |
#6057 |
| Dependabot #128 js-yaml (extensions/vscode) |
true positive, fix available |
4.3.1 → 4.3.2 |
#6057 |
| Dependabot #134 / #133 vitest, @vitest/mocker (web) |
true positive, fix available |
4.1.9 → 4.1.11 |
#6057 |
| Dependabot #131 / #130 vitest, @vitest/mocker (telemetry-ingest) |
true positive, fix available |
4.1.9/4.1.10 → 4.1.11 |
#6057 |
Audits: cd web && npm audit --omit=dev → found 0 vulnerabilities. cargo audit not installed (not run).
Follow-up: provision GITHUB_CODEWHALE_SECURITY_PAT (code scanning R/W) so the CodeQL half of the sweep can run.
Written by Devin
Nightly security & dependency sweep for 2026-09-11.
GITHUB_CODEWHALE_SECURITY_PATnot provisioned; default credential got HTTP 403Resource not accessible by integrationonGET /repos/Hmbown/CodeWhale/code-scanning/alerts. Nothing was dismissed.Audits:
cd web && npm audit --omit=dev→ found 0 vulnerabilities.cargo auditnot installed (not run).Follow-up: provision
GITHUB_CODEWHALE_SECURITY_PAT(code scanning R/W) so the CodeQL half of the sweep can run.Written by Devin