Skip to content

Security hardening + Dependabot remediation#165

Merged
federiconeri merged 2 commits intomainfrom
fix/security-dependabot-checkup
Apr 7, 2026
Merged

Security hardening + Dependabot remediation#165
federiconeri merged 2 commits intomainfrom
fix/security-dependabot-checkup

Conversation

@federiconeri
Copy link
Copy Markdown
Owner

@federiconeri federiconeri commented Apr 7, 2026

Security remediation PR: removed eval execution in feature-loop template, hardened .env.local writes to mode 0600, added .github/dependabot.yml, added CodeQL workflow, enabled code scanning default setup, and updated lockfile via npm audit fix (npm audit now reports 0 vulnerabilities). Validated with npm run typecheck and targeted tests for template/env/config suites. Note: full test run has unrelated pre-existing failures in src/agent/tools/max-length-tool-inputs.integration.test.ts.

@federiconeri federiconeri merged commit 430be31 into main Apr 7, 2026
5 checks passed
@federiconeri federiconeri deleted the fix/security-dependabot-checkup branch April 7, 2026 14:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant