Skip to content

Triage 9 Dependabot vulnerability alerts on main #212

@stultus

Description

@stultus

Context

After enabling vulnerability alerts during the hygiene pass, GitHub immediately surfaced 9 vulnerabilities on `main`:

  • 3 high
  • 4 moderate
  • 2 low

These were reported in the `git push` output during PR #208 work. They split across `npm` and `cargo` ecosystems (Dependabot reports per ecosystem).

Action

  1. Visit https://github.com/stultus/scriptty/security/dependabot for the full list.
  2. For each high-severity alert: assess whether the vulnerable code path is reachable in Scriptty. Many high-severity CVEs in transitive deps are not exploitable in our usage.
  3. Dependabot version-updates (configured in PR chore: add Dependabot config #198) will open patch PRs for fixable issues. For dev-only deps with no upstream fix, decide whether to dismiss with a reason.

Note

Dependabot security PRs land separately from this issue. This issue is the triage tracker — close it once each of the 9 has either been patched or explicitly dismissed.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions