Skip to content

Security backlog cleanup: stabilize CI and handle Dependabot alerts #21

@baderdean

Description

@baderdean

Context\nBacklog cleanup closed multiple blocked Dependabot PRs to reduce noise.\n\n## Remaining security work\n- [ ] Resolve GHSA-wrw7-89jp-8q8g (glib < 0.20.0 via Linux GTK stack)\n- [ ] Assess GHSA-8m95-fffc-h4c5 (libsql-sqlite3-parser crash on invalid UTF-8, no patched version listed)\n- [ ] Re-enable a dependable dependency update flow (grouped updates + passing CI)\n\n## Notes\nCurrent CI is failing broadly on security/rust checks, so isolated bot PRs are not mergeable as-is.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions