Skip to content

fix(security): close remaining scan alerts - #69

Merged
StringKe merged 1 commit into
mainfrom
agent/close-security-alerts
Aug 13, 2026
Merged

fix(security): close remaining scan alerts#69
StringKe merged 1 commit into
mainfrom
agent/close-security-alerts

Conversation

@StringKe

Copy link
Copy Markdown
Owner

Summary

  • keep the Release workflow read-only by default and grant contents: write only to the release job
  • update event-listener in the Linux SDK lockfile from 5.4.1 to 5.4.2
  • remove the now-unused concurrent-queue and crossbeam-utils lock entries

Security context

Verification

  • cargo audit --file sdk/linux/Cargo.lock: 0 vulnerabilities, 0 warnings
  • pnpm audit --prod --audit-level high: no known vulnerabilities
  • pnpm run test:release-contracts: 60 tests PASS
  • pnpm run check: PASS
  • pnpm test: PASS
  • git diff --check: PASS

Signed-off-by: StringKE <stringke.me@gmail.com>
@StringKe
StringKe merged commit 901b76e into main Aug 13, 2026
11 checks passed
StringKe added a commit that referenced this pull request Aug 13, 2026
Bump the repository release version to 0.0.3 and generate release notes for the security hardening merged in PR #69.

Signed-off-by: StringKE <stringke.me@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant