generated from bfra-me/.github
-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Description
Daily Autohealing Report — 2026-03-27 (UTC)
Errored PRs
None. All open PRs have passing CI checks:
Security
- Fixed: Created #3025 to address CVE-2026-33671 (HIGH) and CVE-2026-33672 (MEDIUM) for picomatch.
- CVE-2026-33671 (HIGH): ReDoS vulnerability via extglob quantifiers
- CVE-2026-33672 (MEDIUM): Method Injection in POSIX Character Classes
- Fix: Added `picomatch: >=4.0.4` override to package.json
- picomatch is a transitive dependency via @bfra.me/eslint-config
- Previously Resolved: #3022 (yaml CVE-2026-33532) was merged on 2026-03-26.
Health & Maintenance
- Workflow Actions: All actions are pinned to commit SHAs with version comments. No unpinned actions found.
- Open Dependency Update PRs (awaiting review):
Developer Experience
All validation commands pass on main:
- `pnpm bootstrap` ✓
- `pnpm check-types` ✓
- `pnpm lint` ✓
- `pnpm check-format` ✓
Needs Human Attention
- #3025: HIGH severity security fix for picomatch (CVE-2026-33671) - needs review and merge.
- #3014 and #2997: Dependency update PRs are ready for merge but require review approval.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels