Skip to content

Refresh security dependencies and audit release locks - #21

Merged
philippgerard merged 4 commits into
mainfrom
codex/dependency-security-20260917
Sep 17, 2026
Merged

philippgerard merged 4 commits into
mainfrom
codex/dependency-security-20260917

Conversation

@philippgerard

Copy link
Copy Markdown
Owner

Patch the TLS and HTTP/2 dependencies across the application, vendored transport library, and standalone migrator. Refresh compatible maintenance versions, remove the affected test-only scc dependency, and retain the existing embedding/native-runtime versions.

Release workflows now audit all relevant lockfiles and reject known vulnerabilities, unsound dependencies, and yanked versions before publication. Existing unmaintained-dependency warnings remain visible.

Validation: strict audits pass for all three locks; provider tests and vendored library tests pass; formatting and release security/attestation/shell checks pass. The complete release test/build matrix runs on this pull request.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-17T12:44:51.005191Z a01a5d9 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@philippgerard
philippgerard merged commit fbcabbb into main Sep 17, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant