Skip to content

fix: clear scheduled OSV security findings - #660

Merged
creatornader merged 4 commits into
mainfrom
fix/security-scan-followthrough-20260824
Aug 24, 2026
Merged

fix: clear scheduled OSV security findings#660
creatornader merged 4 commits into
mainfrom
fix/security-scan-followthrough-20260824

Conversation

@creatornader

Copy link
Copy Markdown
Owner

Fixes the scheduled OSV failure by updating the nanoid override to 3.3.18. Records the reviewed extract-zip exception in OSV Scanner with a November 24 expiry and the existing upstream-release monitor. Makes the OpenAI Agents smoke read the installed SDK version, which was verified against Dependabot PR #659 at 0.17.0. Defers the incompatible Changesets v3 Dependabot migration until its patchedDependencies limitation is reviewed. Local validation passed: full workspace tests, lint, doc-sync, and OSV Scanner.

@creatornader
creatornader merged commit eaf59fa into main Aug 24, 2026
24 checks passed
@creatornader
creatornader deleted the fix/security-scan-followthrough-20260824 branch August 24, 2026 21:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant