{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-1ed8f25aa5b9b00d", "name": "Possibly dead Python function: d1", "shortDescription": {"text": "Possibly dead Python function: d1"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9cfdb1a3b5cbf60a", "name": "Possibly dead Python function: d2", "shortDescription": {"text": "Possibly dead Python function: d2"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-713b48b06724c3de", "name": "Possibly dead Python function: d3", "shortDescription": {"text": "Possibly dead Python function: d3"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bcc72456aa4ba790", "name": "Possibly dead Python function: d4", "shortDescription": {"text": "Possibly dead Python function: d4"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cd30640c975805e8", "name": "Possibly dead Python function: d5", "shortDescription": {"text": "Possibly dead Python function: d5"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2629c48467d7bda8", "name": "Possibly dead Python function: d6", "shortDescription": {"text": "Possibly dead Python function: d6"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6920b7b65d7d9aff", "name": "Possibly dead Python function: d7", "shortDescription": {"text": "Possibly dead Python function: d7"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e76243c48deac2f6", "name": "Possibly dead Python function: d8", "shortDescription": {"text": "Possibly dead Python function: d8"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c18aa64ba0479754", "name": "Possibly dead Python function: d9", "shortDescription": {"text": "Possibly dead Python function: d9"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a59bf70c31bc9138", "name": "Possibly dead Python function: run_token_benchmark", "shortDescription": {"text": "Possibly dead Python function: run_token_benchmark"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bf68f65548b1e7b0", "name": "Possibly dead Python function: visit_Name", "shortDescription": {"text": "Possibly dead Python function: visit_Name"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2a68cb1c2f33de0a", "name": "Possibly dead Python function: visit_FunctionDef", "shortDescription": {"text": "Possibly dead Python function: visit_FunctionDef"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-800b78ca5e3e6901", "name": "Possibly dead Python function: visit_AsyncFunctionDef", "shortDescription": {"text": "Possibly dead Python function: visit_AsyncFunctionDef"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-756b916f8687c4e8", "name": "Possibly dead Python function: visit_ClassDef", "shortDescription": {"text": "Possibly dead Python function: visit_ClassDef"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d68334e9565bc97b", "name": "Possibly dead Python function: visit_Lambda", "shortDescription": {"text": "Possibly dead Python function: visit_Lambda"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cacee80b7dab05f6", "name": "Possibly dead Python function: visit_Import", "shortDescription": {"text": "Possibly dead Python function: visit_Import"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7eba5afb1fa27168", "name": "Possibly dead Python function: visit_ImportFrom", "shortDescription": {"text": "Possibly dead Python function: visit_ImportFrom"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-51273acd6d86664e", "name": "Possibly dead Python function: visit_Call", "shortDescription": {"text": "Possibly dead Python function: visit_Call"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-953a637314df4f26", "name": "Possibly dead Python function: visit_If", "shortDescription": {"text": "Possibly dead Python function: visit_If"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-104ca6ed3d607bc4", "name": "Possibly dead Python function: replace_comment", "shortDescription": {"text": "Possibly dead Python function: replace_comment"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ea0fd0d3cedec28", "name": "Possibly dead Python function: save_result", "shortDescription": {"text": "Possibly dead Python function: save_result"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-64efa2328e296640", "name": "Possibly dead Python function: list_memories", "shortDescription": {"text": "Possibly dead Python function: list_memories"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-87b12cc600270924", "name": "Possibly dead Python function: clear_memories", "shortDescription": {"text": "Possibly dead Python function: clear_memories"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b4844f191a964731", "name": "Possibly dead Python function: enrich_jedi_calls", "shortDescription": {"text": "Possibly dead Python function: enrich_jedi_calls"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-39bcf1408de604d7", "name": "Possibly dead Python function: take_snapshot", "shortDescription": {"text": "Possibly dead Python function: take_snapshot"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c076c779faec8e6b", "name": "Possibly dead Python function: save_snapshot", "shortDescription": {"text": "Possibly dead Python function: save_snapshot"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e2471b34306193a", "name": "Possibly dead Python function: load_snapshot", "shortDescription": {"text": "Possibly dead Python function: load_snapshot"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c54a975ea224fef3", "name": "dynamic urllib use detected \u2014 code_review_graph/embeddings.py:293", "shortDescription": {"text": "dynamic urllib use detected \u2014 code_review_graph/embeddings.py:293"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A01:2017 - Injection\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-541694fb0e092f8c", "name": "dynamic urllib use detected \u2014 scripts/diagnose_pypi_connectivity.py:54", "shortDescription": {"text": "dynamic urllib use detected \u2014 scripts/diagnose_pypi_connectivity.py:54"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A01:2017 - Injection\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-fd0f8adede1539b2", "name": "CVE-2026-41425: authlib 1.6.9 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-41425: authlib 1.6.9 \u2014 uv.lock"}, "fullDescription": {"text": "authlib: Authlib: Cross-Site Request Forgery (CSRF) vulnerability in OAuth cache feature\n\nAuthlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth.  This vulnerability is fixed in 1.6.11.\n\nPackage: authlib\nInstalled: 1.6.9\nFixed in: 1.6.11\nSeverity: MEDIUM\nFix: Upgrade authlib to 1.6.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-61be9d0ebae5f57b", "name": "CVE-2026-41479: authlib 1.6.9 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-41479: authlib 1.6.9 \u2014 uv.lock"}, "fullDescription": {"text": "Authlib is a Python library which builds OAuth and OpenID Connect serv ...\n\nAuthlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses an unsupported response_type and supplies an attacker-controlled redirect_uri. The vulnerable behavior happens before client lookup and before any redirect URI validation. As a result, an attacker does not need a valid client registration, an authenticated user, or any prior state. \n\nPackage: authlib\nInstalled: 1.6.9\nFixed in: 1.6.10, 1.7.1\nSeverity: MEDIUM\nFix: Upgrade authlib to 1.6.10, 1.7.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-81247f3ad8f53a65", "name": "CVE-2026-44681: authlib 1.6.9 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-44681: authlib 1.6.9 \u2014 uv.lock"}, "fullDescription": {"text": "Authlib is a Python library which builds OAuth and OpenID Connect serv ...\n\nAuthlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and OpenIDHybridGrant authorization endpoint lets a remote attacker cause the authorization server to issue an HTTP 302 to an attacker-chosen URL by submitting an authorization request that omits the openid scope. This vulnerability is fixed in 1.6.12 and 1.7.1.\n\nPackage: authlib\nInstalled: 1.6.9\nFixed in: 1.7.1, 1.6.12\nSeverity: MEDIUM\nFix: Upgrade authlib to 1.7.1, 1.6.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c5336b6cde629f40", "name": "GHSA-537c-gmf6-5ccf: cryptography 46.0.5 \u2014 uv.lock", "shortDescription": {"text": "GHSA-537c-gmf6-5ccf: cryptography 46.0.5 \u2014 uv.lock"}, "fullDescription": {"text": "Vulnerable OpenSSL included in cryptography wheels\n\npyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt.\n\nIf you are building cryptography source (\"sdist\") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on \n\nPackage: cryptography\nInstalled: 46.0.5\nFixed in: 48.0.1\nSeverity: HIGH\nFix: Upgrade cryptography to 48.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cd5d9fc326eb90c0", "name": "CVE-2026-39892: cryptography 46.0.5 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-39892: cryptography 46.0.5 \u2014 uv.lock"}, "fullDescription": {"text": "cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API\n\ncryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.\n\nPackage: cryptography\nInstalled: 46.0.5\nFixed in: 46.0.7\nSeverity: MEDIUM\nFix: Upgrade cryptography to 46.0.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b5735cdb2841320d", "name": "CVE-2026-34073: cryptography 46.0.5 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34073: cryptography 46.0.5 \u2014 uv.lock"}, "fullDescription": {"text": "python-cryptography: Cryptography: Security bypass due to improper DNS name constraint validation\n\ncryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the \"peer name\" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for b\n\nPackage: cryptography\nInstalled: 46.0.5\nFixed in: 46.0.6\nSeverity: LOW\nFix: Upgrade cryptography to 46.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-206a6aeb11dedddf", "name": "CVE-2026-45409: idna 3.11 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-45409: idna 3.11 \u2014 uv.lock"}, "fullDescription": {"text": "python-idna: idna: Denial of Service via specially crafted long inputs\n\nInternationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fi\n\nPackage: idna\nInstalled: 3.11\nFixed in: 3.15\nSeverity: MEDIUM\nFix: Upgrade idna to 3.15"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e8d6ba8517d23e72", "name": "CVE-2026-52869: mcp 1.26.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-52869: mcp 1.26.0 \u2014 uv.lock"}, "fullDescription": {"text": "MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal\n\nThe MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route requests to existing sessions using only the session_id query parameter or Mcp-Session-Id header without verifying the authenticated principal that created the session, allowing a different bearer-token-authenticated client\n\nPackage: mcp\nInstalled: 1.26.0\nFixed in: 1.27.2\nSeverity: HIGH\nFix: Upgrade mcp to 1.27.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-feb597e31f9086f4", "name": "CVE-2026-52870: mcp 1.26.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-52870: mcp 1.26.0 \u2014 uv.lock"}, "fullDescription": {"text": "MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks\n\nThe MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session that created each task, allowing any connected client to enumerate, read results from, consume messages for, or cancel other clients' tasks. This issue is fixed in version 1.27.2.\n\nPackage: mcp\nInstalled: 1.26.0\nFixed in: 1.27.2\nSeverity: HIGH\nFix: Upgrade mcp to 1.27.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ed443779d57d0e98", "name": "CVE-2026-59950: mcp 1.26.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59950: mcp 1.26.0 \u2014 uv.lock"}, "fullDescription": {"text": "MCP Python SDK: WebSocket server transport does not support Host/Origin validation\n\nThe MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that exposed that transport. This issue is fixed in version 1.28.1.\n\nPackage: mcp\nInstalled: 1.26.0\nFixed in: 1.28.1\nSeverity: HIGH\nFix: Upgrade mcp to 1.28.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ca8bfe770072a982", "name": "CVE-2026-40192: pillow 12.1.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-40192: pillow 12.1.1 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing\n\nPillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.\n\nPackage: pillow\nInstalled: 12.1.1\nFixed in: 12.2.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d2adf6cae79bd898", "name": "CVE-2026-42311: pillow 12.1.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-42311: pillow 12.1.1 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing\n\nPillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 12.1.1\nFixed in: 12.2.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7be7393337ad7e9b", "name": "CVE-2026-54058: pillow 12.1.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54058: pillow 12.1.1 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image\n\nPillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.1.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-724a69f7397f494c", "name": "CVE-2026-54059: pillow 12.1.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54059: pillow 12.1.1 \u2014 uv.lock"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted PCF font data\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.1.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b3734dc4c7bb827e", "name": "CVE-2026-54060: pillow 12.1.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54060: pillow 12.1.1 \u2014 uv.lock"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(\"1\", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.1.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0b87306fb2726d2c", "name": "CVE-2026-55379: pillow 12.1.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-55379: pillow 12.1.1 \u2014 uv.lock"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted BDF font file\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.1.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f05f5f8299ab3a19", "name": "CVE-2026-55380: pillow 12.1.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-55380: pillow 12.1.1 \u2014 uv.lock"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted GD 2.x image file\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.1.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-06d1552b59366417", "name": "CVE-2026-59197: pillow 12.1.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59197: pillow 12.1.1 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Native heap out-of-bounds write\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.1.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bf3b5ec880438ff5", "name": "CVE-2026-59199: pillow 12.1.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59199: pillow 12.1.1 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via out-of-bounds write in image processing\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.1.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-19e738452d3cd1d7", "name": "CVE-2026-59200: pillow 12.1.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59200: pillow 12.1.1 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of service via crafted PDF stream\n\nPillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.1.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-93510f1b6a5261e0", "name": "CVE-2026-59204: pillow 12.1.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59204: pillow 12.1.1 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via crafted JPEG2000 image\n\nPillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.1.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0e7e5b47ca3900a4", "name": "CVE-2026-59205: pillow 12.1.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59205: pillow 12.1.1 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.1.1\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c1627f08bd158383", "name": "CVE-2026-42308: pillow 12.1.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-42308: pillow 12.1.1 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: python: Pillow: Denial of Service via integer overflow in font processing\n\nPillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 12.1.1\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0196d8d5c8df830b", "name": "CVE-2026-42309: pillow 12.1.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-42309: pillow 12.1.1 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via specially crafted coordinate input\n\nPillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates such as ImagePath.Path, ImageDraw.ImageDraw.polygon and ImageDraw.ImageDraw.line could cause a heap buffer overflow, as nested lists were recursively unpacked beyond the allocated buffer. Coordinate lists are now validated to contain exactly two numeric coordinates. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 12.1.1\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-adeed4fa8413bca9", "name": "CVE-2026-42310: pillow 12.1.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-42310: pillow 12.1.1 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via malicious PDF processing\n\nPillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.\n\nPackage: pillow\nInstalled: 12.1.1\nFixed in: 12.2.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e28c8f1a94d496aa", "name": "CVE-2026-55798: pillow 12.1.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-55798: pillow 12.1.1 \u2014 uv.lock"}, "fullDescription": {"text": "python-pillow: Pillow: Arbitrary command injection via shell metacharacters in file paths\n\nPillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.1.1\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3559b73b16add84c", "name": "CVE-2026-59198: pillow 12.1.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59198: pillow 12.1.1 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Information disclosure via TGA RLE encoder out-of-bounds read\n\nPillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.1.1\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0723c1ef2398e321", "name": "CVE-2026-59203: pillow 12.1.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59203: pillow 12.1.1 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via crafted EPS file\n\nPillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing a crafted EPS file to cause Image.open() to seek backwards to the same directive and parse it repeatedly in an infinite loop. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.1.1\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0bf4b6732214b3f2", "name": "CVE-2026-59885: pyasn1 0.6.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59885: pyasn1 0.6.3 \u2014 uv.lock"}, "fullDescription": {"text": "pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values.\n\nPackage: pyasn1\nInstalled: 0.6.3\nFixed in: 0.6.4\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-988094facb9cf24b", "name": "CVE-2026-59886: pyasn1 0.6.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59886: pyasn1 0.6.3 \u2014 uv.lock"}, "fullDescription": {"text": "pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print\n\nPackage: pyasn1\nInstalled: 0.6.3\nFixed in: 0.6.4\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2c9f940291de2b45", "name": "GHSA-4xgf-cpjx-pc3j: pydantic-settings 2.13.1 \u2014 uv.lock", "shortDescription": {"text": "GHSA-4xgf-cpjx-pc3j: pydantic-settings 2.13.1 \u2014 uv.lock"}, "fullDescription": {"text": "pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size\n\n### Summary\n\n`NestedSecretsSettingsSource` reads secret values from files in a configured `secrets_dir`. When `secrets_nested_subdir=True`, a directory entry inside `secrets_dir` that is a symbolic link pointing **outside** `secrets_dir` is followed, so files outside the configured directory are read into settings values. The same code path bypasses the documented `secrets_dir_max_size` protection. An attacker or lower-privileged component able to influence entries in the configured secrets dire\n\nPackage: pydantic-settings\nInstalled: 2.13.1\nFixed in: 2.14.2\nSeverity: MEDIUM\nFix: Upgrade pydantic-settings to 2.14.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0da8a15114591082", "name": "CVE-2026-4539: pygments 2.19.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-4539: pygments 2.19.2 \u2014 uv.lock"}, "fullDescription": {"text": "pygments: Pygments: Denial of Service via inefficient regular expression processing in AdlLexer\n\nA security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.\n\nPackage: pygments\nInstalled: 2.19.2\nFixed in: 2.20.0\nSeverity: LOW\nFix: Upgrade pygments to 2.20.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6514fbdcfaa9204b", "name": "CVE-2026-48526: pyjwt 2.12.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-48526: pyjwt 2.12.1 \u2014 uv.lock"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens\n\nPyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.\n\nPackage: pyjwt\nInstalled: 2.12.1\nFixed in: 2.13.0\nSeverity: HIGH\nFix: Upgrade pyjwt to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-10d45d6df7a6f197", "name": "CVE-2026-48522: pyjwt 2.12.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-48522: pyjwt 2.12.1 \u2014 uv.lock"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Server-Side Request Forgery (SSRF) via uncontrolled URL fetching in PyJWKClient\n\nPyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default OpenerDirector registering HTTPHandler, HTTPSHandler, FTPHandler, FileHandler, and DataHandler. There is currently no documented option to restrict which schemes PyJWKClient will fetch. If an application's jku URL ingestion path accepts attacker-influenced URLs (e.g., from JWT header, configuration file, OAuth flow parame\n\nPackage: pyjwt\nInstalled: 2.12.1\nFixed in: 2.13.0\nSeverity: MEDIUM\nFix: Upgrade pyjwt to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5728cdec0dc11919", "name": "CVE-2026-48523: pyjwt 2.12.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-48523: pyjwt 2.12.1 \u2014 uv.lock"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Verifier-side algorithm bypass leads to unauthorized information access\n\nPyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked against the caller-supplied algorithms allow-list, but signature verification is performed with the algorithm bound to the PyJWK object instead of the header algorithm. An attacker who controls a registered JWK/JWKS private key can sign with a disallowed algorithm, adv\n\nPackage: pyjwt\nInstalled: 2.12.1\nFixed in: 2.13.0\nSeverity: MEDIUM\nFix: Upgrade pyjwt to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4ba6012c73817cff", "name": "CVE-2026-48525: pyjwt 2.12.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-48525: pyjwt 2.12.1 \u2014 uv.lock"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Denial of Service via processing of crafted detached JWS tokens\n\nPyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option (\"b64\": false, RFC 7797), PyJWT performs Base64URL decoding of the compact-serialization payload segment before enforcing the detached-payload rules. For b64=false, PyJWT later discards that decoded payload and replaces it with the caller-provided detached_payload. In practice, this turns the middle segment into an attacker-controlled \u201cwork amplifier\u201d: a\n\nPackage: pyjwt\nInstalled: 2.12.1\nFixed in: 2.13.0\nSeverity: MEDIUM\nFix: Upgrade pyjwt to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-898e5e1bfb2fa7db", "name": "CVE-2026-48524: pyjwt 2.12.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-48524: pyjwt 2.12.1 \u2014 uv.lock"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Denial of Service via unverified JSON Web Token key IDs\n\nPyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown kid value, with no rate limiting. Since kid comes from the unverified token header, an attacker can trigger unlimited outbound requests. The vulnerability surfaces only when a JWKS fetch fails; an attacker can attempt to provoke that with sustained unknown-kid traffic, but the outcome depends on upstream JWKS-endpoint be\n\nPackage: pyjwt\nInstalled: 2.12.1\nFixed in: 2.13.0\nSeverity: LOW\nFix: Upgrade pyjwt to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ceb7d3f88d95d998", "name": "CVE-2025-71176: pytest 8.4.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-71176: pytest 8.4.2 \u2014 uv.lock"}, "fullDescription": {"text": "pytest: pytest: Denial of Service or Privilege Escalation via insecure temporary directory handling\n\npytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.\n\nPackage: pytest\nInstalled: 8.4.2\nFixed in: 9.0.3\nSeverity: MEDIUM\nFix: Upgrade pytest to 9.0.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-45a3f658873f06a0", "name": "CVE-2026-42561: python-multipart 0.0.22 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-42561: python-multipart 0.0.22 \u2014 uv.lock"}, "fullDescription": {"text": "python-multipart: python-multipart: Denial of Service via excessive multipart part headers\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, MultipartParser previously had no limit on the number of part headers or the size of an individual part header. An attacker could send a request with either many repeated headers without terminating the header block or a single very large header value, causing excessive CPU work before request reje\n\nPackage: python-multipart\nInstalled: 0.0.22\nFixed in: 0.0.27\nSeverity: HIGH\nFix: Upgrade python-multipart to 0.0.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2786a9b0b3069b17", "name": "CVE-2026-53539: python-multipart 0.0.22 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-53539: python-multipart 0.0.22 \u2014 uv.lock"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Denial of Service via crafted form-urlencoded bodies\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParser located the field separator with a two step lookup: it first scanned the entire remaining buffer for &, and only when no & existed anywhere ahead did it fall back to scanning for ;. For a body that uses ; as the separator and contains no &, every field iteration performed a full failed & scan over the entire remaining buffer before locating the ne\n\nPackage: python-multipart\nInstalled: 0.0.22\nFixed in: 0.0.30\nSeverity: HIGH\nFix: Upgrade python-multipart to 0.0.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-97b2a0c8c6a3f837", "name": "CVE-2026-40347: python-multipart 0.0.22 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-40347: python-multipart 0.0.22 \u2014 uv.lock"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Denial of Service via crafted multipart/form-data requests\n\nPython-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the next boundary candidate when processing leading CR/LF data and immediately discards epilogue data after the closing boundary.\n\nPackage: python-multipart\nInstalled: 0.0.22\nFixed in: 0.0.26\nSeverity: MEDIUM\nFix: Upgrade python-multipart to 0.0.26"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-03498bee78ee13fc", "name": "CVE-2026-53537: python-multipart 0.0.22 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-53537: python-multipart 0.0.22 \u2014 uv.lock"}, "fullDescription": {"text": "multipart: Python-Multipart: Information disclosure via header parsing discrepancy\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.Message, which transparently applies RFC 2231/5987 decoding. The extended parameter syntax (filename*=charset'lang'value, name*=..., and the filename*0/filename*1 continuation form) is decoded and surfaced under the bare filename/name key, and overrides the plain parameter when both are present. RFC 7578 \u00a74.2 explicitly forbid\n\nPackage: python-multipart\nInstalled: 0.0.22\nFixed in: 0.0.30\nSeverity: LOW\nFix: Upgrade python-multipart to 0.0.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-30a81095cfb209fd", "name": "CVE-2026-53538: python-multipart 0.0.22 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-53538: python-multipart 0.0.22 \u2014 uv.lock"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Information disclosure due to parser differential in form data handling\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, modern browsers, and Python's urllib.parse (since the CVE-2021-23336 fix) treat only & as a separator. This creates a parser differential: the same bytes are tokenized into different fields than a WHATWG compliant intermediary would produce, allowing an attacker to smuggle extra form \n\nPackage: python-multipart\nInstalled: 0.0.22\nFixed in: 0.0.30\nSeverity: LOW\nFix: Upgrade python-multipart to 0.0.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ccf066f01b5cb8b5", "name": "CVE-2026-53540: python-multipart 0.0.22 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-53540: python-multipart 0.0.22 \u2014 uv.lock"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Negative Content-Length in parse_form buffers the entire body in memory\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked read of the request body. A negative Content-Length turned the bounded read into a read-until-EOF, so the entire body was loaded into memory in a single read instead of in fixed-size chunks. This vulnerability is fixed in 0.0.31.\n\nPackage: python-multipart\nInstalled: 0.0.22\nFixed in: 0.0.31\nSeverity: LOW\nFix: Upgrade python-multipart to 0.0.31"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f0bc6a832539e0bf", "name": "CVE-2026-25645: requests 2.32.5 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-25645: requests 2.32.5 \u2014 uv.lock"}, "fullDescription": {"text": "requests: Requests: Security bypass due to predictable temporary file creation\n\nRequests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulner\n\nPackage: requests\nInstalled: 2.32.5\nFixed in: 2.33.0\nSeverity: MEDIUM\nFix: Upgrade requests to 2.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-48fdd935e384c638", "name": "CVE-2026-59890: setuptools 82.0.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59890: setuptools 82.0.1 \u2014 uv.lock"}, "fullDescription": {"text": "setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD)\n\nsetuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.\n\nPackage: setuptools\nInstalled: 82.0.1\nFixed in: 83.0.0\nSeverity: MEDIUM\nFix: Upgrade setuptools to 83.0.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c1918baaeda2a82e", "name": "CVE-2026-48818: starlette 0.52.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-48818: starlette 0.52.1 \u2014 uv.lock"}, "fullDescription": {"text": "starlette: Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows\n\nStarlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\\\attacker.com\\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account\u2019s NTLMv2 credentials for offline cracking or relay even though the HTTP response is only a 404. The issue affects default follow_symlink=False deployments, including frameworks built on Starlette such as Fas\n\nPackage: starlette\nInstalled: 0.52.1\nFixed in: 1.1.0\nSeverity: HIGH\nFix: Upgrade starlette to 1.1.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fa7290bdf7d5e488", "name": "CVE-2026-54283: starlette 0.52.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54283: starlette 0.52.1 \u2014 uv.lock"}, "fullDescription": {"text": "starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS\n\nStarlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced for multipart/form-data, but silently ignored for application/x-www-form-urlencoded. An unauthenticated attacker can therefore send a urlencoded body with an arbitrarily large number of fields or an arbitrarily large field, even when the application configured limits it believed would apply.\n\nPackage: starlette\nInstalled: 0.52.1\nFixed in: 1.3.1\nSeverity: HIGH\nFix: Upgrade starlette to 1.3.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-faf17bae7b85853f", "name": "CVE-2026-48710: starlette 0.52.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-48710: starlette 0.52.1 \u2014 uv.lock"}, "fullDescription": {"text": "starlette: Starlette: Security restriction bypass via malformed HTTP Host header\n\nStarlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) \n\nPackage: starlette\nInstalled: 0.52.1\nFixed in: 1.0.1\nSeverity: MEDIUM\nFix: Upgrade starlette to 1.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c7ce42faf6fe55e8", "name": "CVE-2026-48817: starlette 0.52.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-48817: starlette 0.52.1 \u2014 uv.lock"}, "fullDescription": {"text": "starlette: Starlette: Information disclosure and unintended method execution via non-standard HTTP methods\n\nStarlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting the lookup to a known set of HTTP verbs. When an HTTPEndpoint subclass is registered through Route(...) without an explicit methods= argument, the route does not constrain the method and every method reaches the endpoint. If a non-standard HTTP method whose lo\n\nPackage: starlette\nInstalled: 0.52.1\nFixed in: 1.1.0\nSeverity: MEDIUM\nFix: Upgrade starlette to 1.1.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-914c66c6e81b6efd", "name": "CVE-2026-54282: starlette 0.52.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54282: starlette 0.52.1 \u2014 uv.lock"}, "fullDescription": {"text": "starlette: Starlette: Information disclosure due to improper HTTP request path validation\n\nStarlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating {scheme}://{host}{path} and re-parsing the result, a path that does not begin with / (for example @google.com) moves the authority boundary during re-parsing, so request.url.hostname and request.url.netloc become attacker-controlled. Code that reads request.url.hostname (rather than the Host header \n\nPackage: starlette\nInstalled: 0.52.1\nFixed in: 1.3.0\nSeverity: LOW\nFix: Upgrade starlette to 1.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1004df6c60dddfab", "name": "CVE-2025-3000: torch 2.10.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-3000: torch 2.10.0 \u2014 uv.lock"}, "fullDescription": {"text": "A vulnerability classified as critical has been found in PyTorch 2.6.0 ...\n\nA vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.\n\nPackage: torch\nInstalled: 2.10.0\nFixed in: 2.13.0\nSeverity: LOW\nFix: Upgrade torch to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f1fae0d80ab9394f", "name": "CVE-2026-4372: transformers 4.57.6 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-4372: transformers 4.57.6 \u2014 uv.lock"}, "fullDescription": {"text": "HuggingFace transformers vulnerable to remote code execution\n\nA critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an attacker-controlled HuggingFace Hub repository ID. When a victim loads this model using the standard `AutoModelForCausalLM.from_pretrained()` API, the library downloads and executes arbitrary Python code from the attacker's re\n\nPackage: transformers\nInstalled: 4.57.6\nFixed in: 5.3.0\nSeverity: HIGH\nFix: Upgrade transformers to 5.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5e5e145d4910fd84", "name": "CVE-2026-5241: transformers 4.57.6 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-5241: transformers 4.57.6 \u2014 uv.lock"}, "fullDescription": {"text": "python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting\n\nA vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, is overridden by untrusted serialized configuration data in a nested code path. Specifically, when loading a LightGlue model using `AutoModel.from_pretrained()` with `trust_remote_code=False`, the `Lig\n\nPackage: transformers\nInstalled: 4.57.6\nFixed in: 5.5.0\nSeverity: HIGH\nFix: Upgrade transformers to 5.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e8302bac4a3063d2", "name": "CVE-2026-1839: transformers 4.57.6 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-1839: transformers 4.57.6 \u2014 uv.lock"}, "fullDescription": {"text": "transformers: HuggingFace Transformers: Arbitrary code execution via malicious checkpoint file\n\nA vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line 3059 calls `torch.load()` without the `weights_only=True` parameter. This issue affects all versions of the library supporting `torch>=2.2` when used with PyTorch versions below 2.6, as the `safe_globals()` context manager provides no protection in these versions. An attacker can exploit this vul\n\nPackage: transformers\nInstalled: 4.57.6\nFixed in: 5.0.0rc3\nSeverity: MEDIUM\nFix: Upgrade transformers to 5.0.0rc3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9e9907f3d6ecddd1", "name": "CVE-2026-44431: urllib3 2.6.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-44431: urllib3 2.6.3 \u2014 uv.lock"}, "fullDescription": {"text": "urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers\n\nurllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.\n\nPackage: urllib3\nInstalled: 2.6.3\nFixed in: 2.7.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4b91d7a02dcedfdc", "name": "CVE-2026-44432: urllib3 2.6.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-44432: urllib3 2.6.3 \u2014 uv.lock"}, "fullDescription": {"text": "urllib3: urllib3: Denial of Service due to excessive HTTP response decompression\n\nurllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly \n\nPackage: urllib3\nInstalled: 2.6.3\nFixed in: 2.7.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1d3afc046c6f851f", "name": "AWS-0010: Cloudfront distribution should have Access Logging configured \u2014 tests/fixtures/sample.tf", "shortDescription": {"text": "AWS-0010: Cloudfront distribution should have Access Logging configured \u2014 tests/fixtures/sample.tf"}, "fullDescription": {"text": "Cloudfront distribution should have Access Logging configured\n\nDistribution does not have logging enabled\n\nRule: AWS-0010\nSeverity: MEDIUM\nTarget: tests/fixtures/sample.tf"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b4278c98d18b57d8", "name": "AWS-0011: CloudFront distribution does not have a WAF in front. \u2014 tests/fixtures/sample.tf", "shortDescription": {"text": "AWS-0011: CloudFront distribution does not have a WAF in front. \u2014 tests/fixtures/sample.tf"}, "fullDescription": {"text": "CloudFront distribution does not have a WAF in front.\n\nDistribution does not utilize a WAF.\n\nRule: AWS-0011\nSeverity: HIGH\nTarget: tests/fixtures/sample.tf"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-65a2298c439a7e49", "name": "AWS-0013: CloudFront distribution uses outdated SSL/TLS protocols. \u2014 tests/fixtures/sample.tf", "shortDescription": {"text": "AWS-0013: CloudFront distribution uses outdated SSL/TLS protocols. \u2014 tests/fixtures/sample.tf"}, "fullDescription": {"text": "CloudFront distribution uses outdated SSL/TLS protocols.\n\nDistribution uses an insecure minimum TLS protocol version.\n\nRule: AWS-0013\nSeverity: HIGH\nTarget: tests/fixtures/sample.tf"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-aef6876203d7dbb3", "name": "AWS-0028: aws_instance should activate session tokens for Instance Metadata Service. \u2014 tests/fixtures/sample.tf", "shortDescription": {"text": "AWS-0028: aws_instance should activate session tokens for Instance Metadata Service. \u2014 tests/fixtures/sample.tf"}, "fullDescription": {"text": "aws_instance should activate session tokens for Instance Metadata Service.\n\nInstance does not require IMDS access to require a token.\n\nRule: AWS-0028\nSeverity: HIGH\nTarget: tests/fixtures/sample.tf"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d403f777b4436c95", "name": "AWS-0086: S3 Access block should block public ACL \u2014 tests/fixtures/sample.tf", "shortDescription": {"text": "AWS-0086: S3 Access block should block public ACL \u2014 tests/fixtures/sample.tf"}, "fullDescription": {"text": "S3 Access block should block public ACL\n\nNo public access block so not blocking public acls\n\nRule: AWS-0086\nSeverity: HIGH\nTarget: tests/fixtures/sample.tf"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8ff34176b69ecdbc", "name": "AWS-0087: S3 Access block should block public policy \u2014 tests/fixtures/sample.tf", "shortDescription": {"text": "AWS-0087: S3 Access block should block public policy \u2014 tests/fixtures/sample.tf"}, "fullDescription": {"text": "S3 Access block should block public policy\n\nNo public access block so not blocking public policies\n\nRule: AWS-0087\nSeverity: HIGH\nTarget: tests/fixtures/sample.tf"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-92c463c3e5a6a184", "name": "AWS-0089: S3 Bucket Logging \u2014 tests/fixtures/sample.tf", "shortDescription": {"text": "AWS-0089: S3 Bucket Logging \u2014 tests/fixtures/sample.tf"}, "fullDescription": {"text": "S3 Bucket Logging\n\nBucket has logging disabled\n\nRule: AWS-0089\nSeverity: LOW\nTarget: tests/fixtures/sample.tf"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ed6d274797e09e31", "name": "AWS-0090: S3 Data should be versioned \u2014 tests/fixtures/sample.tf", "shortDescription": {"text": "AWS-0090: S3 Data should be versioned \u2014 tests/fixtures/sample.tf"}, "fullDescription": {"text": "S3 Data should be versioned\n\nBucket does not have versioning enabled\n\nRule: AWS-0090\nSeverity: MEDIUM\nTarget: tests/fixtures/sample.tf"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aa7ffddac4beab51", "name": "AWS-0091: S3 Access Block should Ignore Public ACL \u2014 tests/fixtures/sample.tf", "shortDescription": {"text": "AWS-0091: S3 Access Block should Ignore Public ACL \u2014 tests/fixtures/sample.tf"}, "fullDescription": {"text": "S3 Access Block should Ignore Public ACL\n\nNo public access block so not blocking public acls\n\nRule: AWS-0091\nSeverity: HIGH\nTarget: tests/fixtures/sample.tf"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9c8cac6d9aa76956", "name": "AWS-0093: S3 Access block should restrict public bucket to limit access \u2014 tests/fixtures/sample.tf", "shortDescription": {"text": "AWS-0093: S3 Access block should restrict public bucket to limit access \u2014 tests/fixtures/sample.tf"}, "fullDescription": {"text": "S3 Access block should restrict public bucket to limit access\n\nNo public access block so not restricting public buckets\n\nRule: AWS-0093\nSeverity: HIGH\nTarget: tests/fixtures/sample.tf"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e1dfa45741968f1b", "name": "AWS-0094: S3 buckets should each define an aws_s3_bucket_public_access_block \u2014 tests/fixtures/sample.tf", "shortDescription": {"text": "AWS-0094: S3 buckets should each define an aws_s3_bucket_public_access_block \u2014 tests/fixtures/sample.tf"}, "fullDescription": {"text": "S3 buckets should each define an aws_s3_bucket_public_access_block\n\nBucket does not have a corresponding public access block.\n\nRule: AWS-0094\nSeverity: LOW\nTarget: tests/fixtures/sample.tf"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ec849873b2ff7fde", "name": "AWS-0099: Missing description for security group. \u2014 tests/fixtures/sample.tf", "shortDescription": {"text": "AWS-0099: Missing description for security group. \u2014 tests/fixtures/sample.tf"}, "fullDescription": {"text": "Missing description for security group.\n\nSecurity group explicitly uses the default description.\n\nRule: AWS-0099\nSeverity: LOW\nTarget: tests/fixtures/sample.tf"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-74d732e4441a1ee8", "name": "AWS-0131: Instance with unencrypted block device. \u2014 tests/fixtures/sample.tf", "shortDescription": {"text": "AWS-0131: Instance with unencrypted block device. \u2014 tests/fixtures/sample.tf"}, "fullDescription": {"text": "Instance with unencrypted block device.\n\nRoot block device is not encrypted.\n\nRule: AWS-0131\nSeverity: HIGH\nTarget: tests/fixtures/sample.tf"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f8d8f2c7c0f0b274", "name": "AWS-0132: S3 encryption should use Customer Managed Keys \u2014 tests/fixtures/sample.tf", "shortDescription": {"text": "AWS-0132: S3 encryption should use Customer Managed Keys \u2014 tests/fixtures/sample.tf"}, "fullDescription": {"text": "S3 encryption should use Customer Managed Keys\n\nBucket does not encrypt data with a customer managed key.\n\nRule: AWS-0132\nSeverity: HIGH\nTarget: tests/fixtures/sample.tf"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c5ba387128707ed3", "name": "AWS-0178: VPC Flow Logs is a feature that enables you to capture information about the IP traffic going to and from netw", "shortDescription": {"text": "AWS-0178: VPC Flow Logs is a feature that enables you to capture information about the IP traffic going to and from network interfaces in your VPC. After you've created a flow log, you can view and retrieve its data in Amazon CloudWatch Log"}, "fullDescription": {"text": "VPC Flow Logs is a feature that enables you to capture information about the IP traffic going to and from network interfaces in your VPC. After you've created a flow log, you can view and retrieve its data in Amazon CloudWatch Logs. It is recommended that VPC Flow Logs be enabled for packet \"Rejects\" for VPCs.\n\nVPC does not have VPC Flow Logs enabled.\n\nRule: AWS-0178\nSeverity: MEDIUM\nTarget: tests/fixtures/sample.tf"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cc55229a7a3c078d", "name": "Agent authority lacks a verifier contract: .mcp.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .mcp.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1374f6c12aca44ef", "name": "Agent authority lacks a verifier contract: skills/build-graph/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: skills/build-graph/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5bb7f44128a743ce", "name": "Agent authority lacks a verifier contract: skills/debug-issue/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: skills/debug-issue/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5d75407ba9df972d", "name": "Agent authority lacks a verifier contract: skills/explore-codebase/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: skills/explore-codebase/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e725d2ab884fbd49", "name": "Multiple root agent instruction files without precedence", "shortDescription": {"text": "Multiple root agent instruction files without precedence"}, "fullDescription": {"text": "The repo has multiple top-level AI-coder instruction files. Without precedence rules, different agents may follow different policies."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e637c415447867e4", "name": "Run SkillSpector's LLM-backed analysis in your own pipeline", "shortDescription": {"text": "Run SkillSpector's LLM-backed analysis in your own pipeline"}, "fullDescription": {"text": "Repobility ran SkillSpector's static rules server-side. The deeper LLM-backed analyzers \u2014 tool-poisoning (TP*), semantic security discovery (SSD*), developer-intent mismatch (SDI*) \u2014 are meant to run on YOUR machine with YOUR model; repobility never sends your code to an LLM. Recipe:\n\n# 1. Install SkillSpector in your own isolated env\npipx install \"skillspector @ git+https://github.com/NVIDIA/SkillSpector.git\"\n\n# 2. Point it at YOUR LLM pipeline (pick one) - your code stays on your machine\nexport SKILLSPECTOR_PROVIDER=anthropic && export ANTHROPIC_API_KEY=sk-ant-...\n# export SKILLSPECTOR_PROVIDER=openai   && export OPENAI_API_KEY=sk-...\n# export SKILLSPECTOR_PROVIDER=openai OPENAI_API_KEY=ollama OPENAI_BASE_URL=http://localhost:11434/v1 SKILLSPECTOR_MODEL=llama3.1:8b\n# export SKILLSPECTOR_PROVIDER=nv_build && export NVIDIA_INFERENCE_KEY=nvapi-...\n\n# 3. Run the LLM-backed scan per skill (omit --no-llm to enable the LLM analyzers)\nskillspector scan skills/build-graph --format sarif --out"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-22eb1ca4a4a0b655", "name": "Insecure pattern 'insert_adjacent_html' in code_review_graph/visualization.py:829", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in code_review_graph/visualization.py:829"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-e4290e1c65eed254", "name": "Insecure pattern 'direct_innerhtml_assignment' in code-review-graph-vscode/src/webview/graph.ts:670", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in code-review-graph-vscode/src/webview/graph.ts:670"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-41f42c7b617f44e1", "name": "Insecure pattern 'eval_used' in .github/workflows/eval.yml:56", "shortDescription": {"text": "Insecure pattern 'eval_used' in .github/workflows/eval.yml:56"}, "fullDescription": {"text": "Found a known-risky pattern (eval_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5d2dba911b3e3517", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/setup-python@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-27924aa79fa4a517", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/setup-python@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c3f98450e67bb718", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/download-artifact@v8 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d5c51560effec079", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/upload-artifact@v7 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a53bf972e19b52fd", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/setup-python@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7e53db065dcd3489", "name": "Very large file: tests/test_parser.py (1518 lines)", "shortDescription": {"text": "Very large file: tests/test_parser.py (1518 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2fb7eb6adbfeab40", "name": "Very large file: tests/test_skills.py (2189 lines)", "shortDescription": {"text": "Very large file: tests/test_skills.py (2189 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0082b4ba3a556d3c", "name": "Very large file: tests/test_multilang.py (3669 lines)", "shortDescription": {"text": "Very large file: tests/test_multilang.py (3669 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8c91d22584884882", "name": "Very large file: tests/test_tools.py (2092 lines)", "shortDescription": {"text": "Very large file: tests/test_tools.py (2092 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-29c71b3dab52081e", "name": "Very large file: code_review_graph/parser.py (14182 lines)", "shortDescription": {"text": "Very large file: code_review_graph/parser.py (14182 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-26272a619f08632a", "name": "Very large file: code_review_graph/skills.py (1713 lines)", "shortDescription": {"text": "Very large file: code_review_graph/skills.py (1713 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-49acc8c09f06bdbc", "name": "Very large file: code_review_graph/graph.py (1633 lines)", "shortDescription": {"text": "Very large file: code_review_graph/graph.py (1633 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a0fe836eb94cbaa7", "name": "Very large file: code_review_graph/cli.py (1783 lines)", "shortDescription": {"text": "Very large file: code_review_graph/cli.py (1783 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea11ed5d22a6d842", "name": "Very large file: code_review_graph/visualization.py (2234 lines)", "shortDescription": {"text": "Very large file: code_review_graph/visualization.py (2234 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 165 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 34 placeholder/mock markers across 10 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d662004ab2a1a2c9", "name": "Stub function `add` (body is just `pass`/`return`) \u2014 code_review_graph/parser.py:5486", "shortDescription": {"text": "Stub function `add` (body is just `pass`/`return`) \u2014 code_review_graph/parser.py:5486"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-095a2ab0b0b796fb", "name": "Legacy-named symbol `_migrate_v2` in code_review_graph/migrations.py:74", "shortDescription": {"text": "Legacy-named symbol `_migrate_v2` in code_review_graph/migrations.py:74"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2e1c04c39d7ea17d", "name": "Network/subprocess call without timeout or try/except \u2014 code_review_graph/daemon.py:1058", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 code_review_graph/daemon.py:1058"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-ec349c8142f6b07e", "name": "Stub function `embed` (body is just `pass`/`return`) \u2014 code_review_graph/embeddings.py:48", "shortDescription": {"text": "Stub function `embed` (body is just `pass`/`return`) \u2014 code_review_graph/embeddings.py:48"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-20146c64919188a2", "name": "Network/subprocess call without timeout or try/except \u2014 code_review_graph/eval/runner.py:97", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 code_review_graph/eval/runner.py:97"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-0eacf55a92f0e83a", "name": "Network/subprocess call without timeout or try/except \u2014 code_review_graph/eval/benchmarks/token_efficiency.py:28", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 code_review_graph/eval/benchmarks/token_efficiency.py:28"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-9de5f4a8380ccd03", "name": "Network/subprocess call without timeout or try/except \u2014 code_review_graph/eval/benchmarks/impact_accuracy.py:35", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 code_review_graph/eval/benchmarks/impact_accuracy.py:35"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-8df7778a2c07d890", "name": "Vulnerable dependency esbuild 0.20.2: GHSA-67mh-4wv8-2f99", "shortDescription": {"text": "Vulnerable dependency esbuild 0.20.2: GHSA-67mh-4wv8-2f99"}, "fullDescription": {"text": "OSV.dev reports `esbuild` at version `0.20.2` (resolved in `code-review-graph-vscode/package-lock.json`) is affected by GHSA-67mh-4wv8-2f99.\n\nesbuild enables any website to send any requests to the development server and read the response\n\nAdvisory: https://osv.dev/vulnerability/GHSA-67mh-4wv8-2f99\nFix: upgrade `esbuild` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-31c55f92e38390ae", "name": "Vulnerable dependency mcp 1.26.0: GHSA-hvrp-rf83-w775", "shortDescription": {"text": "Vulnerable dependency mcp 1.26.0: GHSA-hvrp-rf83-w775"}, "fullDescription": {"text": "OSV.dev reports `mcp` at version `1.26.0` (resolved in `uv.lock`) is affected by GHSA-hvrp-rf83-w775.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hvrp-rf83-w775\nFix: upgrade `mcp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-013c1a6cb91e1208", "name": "Vulnerable dependency mcp 1.26.0: GHSA-jpw9-pfvf-9f58", "shortDescription": {"text": "Vulnerable dependency mcp 1.26.0: GHSA-jpw9-pfvf-9f58"}, "fullDescription": {"text": "OSV.dev reports `mcp` at version `1.26.0` (resolved in `uv.lock`) is affected by GHSA-jpw9-pfvf-9f58.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jpw9-pfvf-9f58\nFix: upgrade `mcp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-db23505d0ca43798", "name": "Vulnerable dependency mcp 1.26.0: GHSA-vj7q-gjh5-988w", "shortDescription": {"text": "Vulnerable dependency mcp 1.26.0: GHSA-vj7q-gjh5-988w"}, "fullDescription": {"text": "OSV.dev reports `mcp` at version `1.26.0` (resolved in `uv.lock`) is affected by GHSA-vj7q-gjh5-988w.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vj7q-gjh5-988w\nFix: upgrade `mcp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7de3f4e26f938151", "name": "Vulnerable dependency mcp 1.26.0: PYSEC-2026-3481", "shortDescription": {"text": "Vulnerable dependency mcp 1.26.0: PYSEC-2026-3481"}, "fullDescription": {"text": "OSV.dev reports `mcp` at version `1.26.0` (resolved in `uv.lock`) is affected by PYSEC-2026-3481.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3481\nFix: upgrade `mcp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c37a69a109c975c8", "name": "Vulnerable dependency mcp 1.26.0: PYSEC-2026-3482", "shortDescription": {"text": "Vulnerable dependency mcp 1.26.0: PYSEC-2026-3482"}, "fullDescription": {"text": "OSV.dev reports `mcp` at version `1.26.0` (resolved in `uv.lock`) is affected by PYSEC-2026-3482.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3482\nFix: upgrade `mcp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2f770ca3a3d8759f", "name": "Vulnerable dependency mcp 1.26.0: PYSEC-2026-3483", "shortDescription": {"text": "Vulnerable dependency mcp 1.26.0: PYSEC-2026-3483"}, "fullDescription": {"text": "OSV.dev reports `mcp` at version `1.26.0` (resolved in `uv.lock`) is affected by PYSEC-2026-3483.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3483\nFix: upgrade `mcp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8bf960b79a4f13f6", "name": "Vulnerable dependency pytest 8.4.2: GHSA-6w46-j5rx-g56g", "shortDescription": {"text": "Vulnerable dependency pytest 8.4.2: GHSA-6w46-j5rx-g56g"}, "fullDescription": {"text": "OSV.dev reports `pytest` at version `8.4.2` (resolved in `uv.lock`) is affected by GHSA-6w46-j5rx-g56g.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6w46-j5rx-g56g\nFix: upgrade `pytest` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-4e4a8e70187fa015", "name": "Vulnerable dependency pytest 8.4.2: PYSEC-2026-1845", "shortDescription": {"text": "Vulnerable dependency pytest 8.4.2: PYSEC-2026-1845"}, "fullDescription": {"text": "OSV.dev reports `pytest` at version `8.4.2` (resolved in `uv.lock`) is affected by PYSEC-2026-1845.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-1845\nFix: upgrade `pytest` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-10168b55251b60df", "name": "Vulnerable dependency brace-expansion 1.1.12: GHSA-3jxr-9vmj-r5cp", "shortDescription": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-3jxr-9vmj-r5cp"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `1.1.12` (resolved in `code-review-graph-vscode/package-lock.json`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups\n\nAliases: CVE-2026-13149\nAdvisory: https://osv.dev/vulnerability/GHSA-3jxr-9vmj-r5cp\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-b8deafc87a401a66", "name": "Vulnerable dependency brace-expansion 1.1.12: GHSA-f886-m6hf-6m8v", "shortDescription": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-f886-m6hf-6m8v"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `1.1.12` (resolved in `code-review-graph-vscode/package-lock.json`) is affected by GHSA-f886-m6hf-6m8v.\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-f886-m6hf-6m8v\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-ef61ade861eb31d7", "name": "Vulnerable dependency form-data 4.0.5: GHSA-hmw2-7cc7-3qxx", "shortDescription": {"text": "Vulnerable dependency form-data 4.0.5: GHSA-hmw2-7cc7-3qxx"}, "fullDescription": {"text": "OSV.dev reports `form-data` at version `4.0.5` (resolved in `code-review-graph-vscode/package-lock.json`) is affected by GHSA-hmw2-7cc7-3qxx.\nNote: `form-data` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hmw2-7cc7-3qxx\nFix: upgrade `form-data` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-47578c9cb1ee419d", "name": "Vulnerable dependency linkify-it 3.0.3: GHSA-22p9-wv53-3rq4", "shortDescription": {"text": "Vulnerable dependency linkify-it 3.0.3: GHSA-22p9-wv53-3rq4"}, "fullDescription": {"text": "OSV.dev reports `linkify-it` at version `3.0.3` (resolved in `code-review-graph-vscode/package-lock.json`) is affected by GHSA-22p9-wv53-3rq4 (aka CVE-2026-48801).\nNote: `linkify-it` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nLinkifyIt#match scan loop has quadratic algorithmic complexity\n\nAliases: CVE-2026-48801\nAdvisory: https://osv.dev/vulnerability/GHSA-22p9-wv53-3rq4\nFix: upgrade `linkify-it` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-137c0886e1efbf85", "name": "Vulnerable dependency linkify-it 3.0.3: GHSA-v245-v573-v5vm", "shortDescription": {"text": "Vulnerable dependency linkify-it 3.0.3: GHSA-v245-v573-v5vm"}, "fullDescription": {"text": "OSV.dev reports `linkify-it` at version `3.0.3` (resolved in `code-review-graph-vscode/package-lock.json`) is affected by GHSA-v245-v573-v5vm.\nNote: `linkify-it` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v245-v573-v5vm\nFix: upgrade `linkify-it` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-dece238f02200800", "name": "Vulnerable dependency markdown-it 12.3.2: GHSA-6v5v-wf23-fmfq", "shortDescription": {"text": "Vulnerable dependency markdown-it 12.3.2: GHSA-6v5v-wf23-fmfq"}, "fullDescription": {"text": "OSV.dev reports `markdown-it` at version `12.3.2` (resolved in `code-review-graph-vscode/package-lock.json`) is affected by GHSA-6v5v-wf23-fmfq.\nNote: `markdown-it` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6v5v-wf23-fmfq\nFix: upgrade `markdown-it` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-582d6a8fd069c942", "name": "Vulnerable dependency qs 6.15.0: GHSA-q8mj-m7cp-5q26", "shortDescription": {"text": "Vulnerable dependency qs 6.15.0: GHSA-q8mj-m7cp-5q26"}, "fullDescription": {"text": "OSV.dev reports `qs` at version `6.15.0` (resolved in `code-review-graph-vscode/package-lock.json`) is affected by GHSA-q8mj-m7cp-5q26.\nNote: `qs` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q8mj-m7cp-5q26\nFix: upgrade `qs` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-5e90641b6eb585c2", "name": "Vulnerable dependency tmp 0.2.5: GHSA-ph9p-34f9-6g65", "shortDescription": {"text": "Vulnerable dependency tmp 0.2.5: GHSA-ph9p-34f9-6g65"}, "fullDescription": {"text": "OSV.dev reports `tmp` at version `0.2.5` (resolved in `code-review-graph-vscode/package-lock.json`) is affected by GHSA-ph9p-34f9-6g65.\nNote: `tmp` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-ph9p-34f9-6g65\nFix: upgrade `tmp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-a9515e0af2bd3637", "name": "Vulnerable dependency undici 7.24.4: GHSA-35p6-xmwp-9g52", "shortDescription": {"text": "Vulnerable dependency undici 7.24.4: GHSA-35p6-xmwp-9g52"}, "fullDescription": {"text": "OSV.dev reports `undici` at version `7.24.4` (resolved in `code-review-graph-vscode/package-lock.json`) is affected by GHSA-35p6-xmwp-9g52 (aka CVE-2026-6733).\nNote: `undici` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nundici vulnerable to HTTP response queue poisoning via keep-alive socket reuse\n\nAliases: CVE-2026-6733\nAdvisory: https://osv.dev/vulnerability/GHSA-35p6-xmwp-9g52\nFix: upgrade `undici` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-a8a5a095709d1612", "name": "Vulnerable dependency undici 7.24.4: GHSA-g8m3-5g58-fq7m", "shortDescription": {"text": "Vulnerable dependency undici 7.24.4: GHSA-g8m3-5g58-fq7m"}, "fullDescription": {"text": "OSV.dev reports `undici` at version `7.24.4` (resolved in `code-review-graph-vscode/package-lock.json`) is affected by GHSA-g8m3-5g58-fq7m (aka CVE-2026-11525).\nNote: `undici` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nundici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching\n\nAliases: CVE-2026-11525\nAdvisory: https://osv.dev/vulnerability/GHSA-g8m3-5g58-fq7m\nFix: upgrade `undici` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-3d68c82312856e2f", "name": "Vulnerable dependency undici 7.24.4: GHSA-hm92-r4w5-c3mj", "shortDescription": {"text": "Vulnerable dependency undici 7.24.4: GHSA-hm92-r4w5-c3mj"}, "fullDescription": {"text": "OSV.dev reports `undici` at version `7.24.4` (resolved in `code-review-graph-vscode/package-lock.json`) is affected by GHSA-hm92-r4w5-c3mj.\nNote: `undici` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hm92-r4w5-c3mj\nFix: upgrade `undici` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-9a23c65275c433b4", "name": "Vulnerable dependency undici 7.24.4: GHSA-p88m-4jfj-68fv", "shortDescription": {"text": "Vulnerable dependency undici 7.24.4: GHSA-p88m-4jfj-68fv"}, "fullDescription": {"text": "OSV.dev reports `undici` at version `7.24.4` (resolved in `code-review-graph-vscode/package-lock.json`) is affected by GHSA-p88m-4jfj-68fv (aka CVE-2026-9679).\nNote: `undici` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nundici vulnerable to HTTP header injection via Set-Cookie percent-decoding\n\nAliases: CVE-2026-9679\nAdvisory: https://osv.dev/vulnerability/GHSA-p88m-4jfj-68fv\nFix: upgrade `undici` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-618e4472e678bf64", "name": "Vulnerable dependency undici 7.24.4: GHSA-pr7r-676h-xcf6", "shortDescription": {"text": "Vulnerable dependency undici 7.24.4: GHSA-pr7r-676h-xcf6"}, "fullDescription": {"text": "OSV.dev reports `undici` at version `7.24.4` (resolved in `code-review-graph-vscode/package-lock.json`) is affected by GHSA-pr7r-676h-xcf6 (aka CVE-2026-9678).\nNote: `undici` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nundici vulnerable to cross-user information disclosure via shared cache whitespace bypass\n\nAliases: CVE-2026-9678\nAdvisory: https://osv.dev/vulnerability/GHSA-pr7r-676h-xcf6\nFix: upgrade `undici` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-4086cda2616be531", "name": "Vulnerable dependency undici 7.24.4: GHSA-vmh5-mc38-953g", "shortDescription": {"text": "Vulnerable dependency undici 7.24.4: GHSA-vmh5-mc38-953g"}, "fullDescription": {"text": "OSV.dev reports `undici` at version `7.24.4` (resolved in `code-review-graph-vscode/package-lock.json`) is affected by GHSA-vmh5-mc38-953g (aka CVE-2026-9697).\nNote: `undici` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nundici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent\n\nAliases: CVE-2026-9697\nAdvisory: https://osv.dev/vulnerability/GHSA-vmh5-mc38-953g\nFix: upgrade `undici` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-3a359e3a8eeda44f", "name": "Vulnerable dependency undici 7.24.4: GHSA-vxpw-j846-p89q", "shortDescription": {"text": "Vulnerable dependency undici 7.24.4: GHSA-vxpw-j846-p89q"}, "fullDescription": {"text": "OSV.dev reports `undici` at version `7.24.4` (resolved in `code-review-graph-vscode/package-lock.json`) is affected by GHSA-vxpw-j846-p89q (aka CVE-2026-12151).\nNote: `undici` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nundici WebSocket client vulnerable to denial of service via fragment count bypass\n\nAliases: CVE-2026-12151\nAdvisory: https://osv.dev/vulnerability/GHSA-vxpw-j846-p89q\nFix: upgrade `undici` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-104b90bc80ecf1b8", "name": "Vulnerable dependency uuid 8.3.2: GHSA-w5hq-g745-h8pq", "shortDescription": {"text": "Vulnerable dependency uuid 8.3.2: GHSA-w5hq-g745-h8pq"}, "fullDescription": {"text": "OSV.dev reports `uuid` at version `8.3.2` (resolved in `code-review-graph-vscode/package-lock.json`) is affected by GHSA-w5hq-g745-h8pq.\nNote: `uuid` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w5hq-g745-h8pq\nFix: upgrade `uuid` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-228596b9db26a39a", "name": "Vulnerable dependency authlib 1.6.9: GHSA-jj8c-mmj3-mmgv", "shortDescription": {"text": "Vulnerable dependency authlib 1.6.9: GHSA-jj8c-mmj3-mmgv"}, "fullDescription": {"text": "OSV.dev reports `authlib` at version `1.6.9` (resolved in `uv.lock`) is affected by GHSA-jj8c-mmj3-mmgv.\nNote: `authlib` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jj8c-mmj3-mmgv\nFix: upgrade `authlib` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-e04c51e47cd6f34e", "name": "Vulnerable dependency authlib 1.6.9: GHSA-r95x-qfjj-fjj2", "shortDescription": {"text": "Vulnerable dependency authlib 1.6.9: GHSA-r95x-qfjj-fjj2"}, "fullDescription": {"text": "OSV.dev reports `authlib` at version `1.6.9` (resolved in `uv.lock`) is affected by GHSA-r95x-qfjj-fjj2.\nNote: `authlib` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r95x-qfjj-fjj2\nFix: upgrade `authlib` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-2460e67d9ae67a48", "name": "Vulnerable dependency authlib 1.6.9: GHSA-w8p2-r796-3vmq", "shortDescription": {"text": "Vulnerable dependency authlib 1.6.9: GHSA-w8p2-r796-3vmq"}, "fullDescription": {"text": "OSV.dev reports `authlib` at version `1.6.9` (resolved in `uv.lock`) is affected by GHSA-w8p2-r796-3vmq.\nNote: `authlib` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w8p2-r796-3vmq\nFix: upgrade `authlib` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-a8f25b38c7e5c630", "name": "Vulnerable dependency authlib 1.6.9: PYSEC-2026-188", "shortDescription": {"text": "Vulnerable dependency authlib 1.6.9: PYSEC-2026-188"}, "fullDescription": {"text": "OSV.dev reports `authlib` at version `1.6.9` (resolved in `uv.lock`) is affected by PYSEC-2026-188.\nNote: `authlib` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-188\nFix: upgrade `authlib` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-8008a828705b7d9b", "name": "Vulnerable dependency authlib 1.6.9: PYSEC-2026-2119", "shortDescription": {"text": "Vulnerable dependency authlib 1.6.9: PYSEC-2026-2119"}, "fullDescription": {"text": "OSV.dev reports `authlib` at version `1.6.9` (resolved in `uv.lock`) is affected by PYSEC-2026-2119.\nNote: `authlib` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2119\nFix: upgrade `authlib` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-9e7fcd6291dd8889", "name": "Vulnerable dependency authlib 1.6.9: PYSEC-2026-25", "shortDescription": {"text": "Vulnerable dependency authlib 1.6.9: PYSEC-2026-25"}, "fullDescription": {"text": "OSV.dev reports `authlib` at version `1.6.9` (resolved in `uv.lock`) is affected by PYSEC-2026-25.\nNote: `authlib` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-25\nFix: upgrade `authlib` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-5ad35f96d45e1160", "name": "Vulnerable dependency click 8.3.1: PYSEC-2026-2132", "shortDescription": {"text": "Vulnerable dependency click 8.3.1: PYSEC-2026-2132"}, "fullDescription": {"text": "OSV.dev reports `click` at version `8.3.1` (resolved in `uv.lock`) is affected by PYSEC-2026-2132.\nNote: `click` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2132\nFix: upgrade `click` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-56f30e4e335cd941", "name": "Vulnerable dependency cryptography 46.0.5: GHSA-537c-gmf6-5ccf", "shortDescription": {"text": "Vulnerable dependency cryptography 46.0.5: GHSA-537c-gmf6-5ccf"}, "fullDescription": {"text": "OSV.dev reports `cryptography` at version `46.0.5` (resolved in `uv.lock`) is affected by GHSA-537c-gmf6-5ccf.\nNote: `cryptography` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nVulnerable OpenSSL included in cryptography wheels\n\nAdvisory: https://osv.dev/vulnerability/GHSA-537c-gmf6-5ccf\nFix: upgrade `cryptography` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2c1fe042cd666315", "name": "Vulnerable dependency cryptography 46.0.5: GHSA-m959-cc7f-wv43", "shortDescription": {"text": "Vulnerable dependency cryptography 46.0.5: GHSA-m959-cc7f-wv43"}, "fullDescription": {"text": "OSV.dev reports `cryptography` at version `46.0.5` (resolved in `uv.lock`) is affected by GHSA-m959-cc7f-wv43.\nNote: `cryptography` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-m959-cc7f-wv43\nFix: upgrade `cryptography` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-ed5ae94bd58f2494", "name": "Vulnerable dependency cryptography 46.0.5: GHSA-p423-j2cm-9vmq", "shortDescription": {"text": "Vulnerable dependency cryptography 46.0.5: GHSA-p423-j2cm-9vmq"}, "fullDescription": {"text": "OSV.dev reports `cryptography` at version `46.0.5` (resolved in `uv.lock`) is affected by GHSA-p423-j2cm-9vmq.\nNote: `cryptography` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-p423-j2cm-9vmq\nFix: upgrade `cryptography` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-50bc92ac457cfd47", "name": "Vulnerable dependency cryptography 46.0.5: PYSEC-2026-35", "shortDescription": {"text": "Vulnerable dependency cryptography 46.0.5: PYSEC-2026-35"}, "fullDescription": {"text": "OSV.dev reports `cryptography` at version `46.0.5` (resolved in `uv.lock`) is affected by PYSEC-2026-35.\nNote: `cryptography` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-35\nFix: upgrade `cryptography` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-75b8a847d15ce6af", "name": "Vulnerable dependency cryptography 46.0.5: PYSEC-2026-36", "shortDescription": {"text": "Vulnerable dependency cryptography 46.0.5: PYSEC-2026-36"}, "fullDescription": {"text": "OSV.dev reports `cryptography` at version `46.0.5` (resolved in `uv.lock`) is affected by PYSEC-2026-36.\nNote: `cryptography` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-36\nFix: upgrade `cryptography` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-fe17a667e654d9a8", "name": "Vulnerable dependency httplib2 0.31.2: PYSEC-2026-3444", "shortDescription": {"text": "Vulnerable dependency httplib2 0.31.2: PYSEC-2026-3444"}, "fullDescription": {"text": "OSV.dev reports `httplib2` at version `0.31.2` (resolved in `uv.lock`) is affected by PYSEC-2026-3444.\nNote: `httplib2` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3444\nFix: upgrade `httplib2` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-9eb78ac091ef83de", "name": "Vulnerable dependency idna 3.11: GHSA-65pc-fj4g-8rjx", "shortDescription": {"text": "Vulnerable dependency idna 3.11: GHSA-65pc-fj4g-8rjx"}, "fullDescription": {"text": "OSV.dev reports `idna` at version `3.11` (resolved in `uv.lock`) is affected by GHSA-65pc-fj4g-8rjx (aka CVE-2026-45409).\nNote: `idna` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nInternationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix\n\nAliases: CVE-2026-45409, PYSEC-2026-215\nAdvisory: https://osv.dev/vulnerability/GHSA-65pc-fj4g-8rjx\nFix: upgrade `idna` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-4c4819f412cee4dc", "name": "Vulnerable dependency pillow 12.1.1: GHSA-45hq-cxwh-f6vc", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-45hq-cxwh-f6vc"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by GHSA-45hq-cxwh-f6vc (aka CVE-2026-55379).\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nPillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` \u2014 bomb protection bypass via font loading\n\nAliases: BIT-pillow-2026-55379, CVE-2026-55379, PYSEC-2026-2255\nAdvisory: https://osv.dev/vulnerability/GHSA-45hq-cxwh-f6vc\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-5f8921bf03f2406a", "name": "Vulnerable dependency pillow 12.1.1: GHSA-4x4j-2g7c-83w6", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-4x4j-2g7c-83w6"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by GHSA-4x4j-2g7c-83w6 (aka CVE-2026-55798).\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nPillow: WindowsViewer.get_command() OS command injection via unescaped shell path\n\nAliases: BIT-pillow-2026-55798, CVE-2026-55798, PYSEC-2026-2257\nAdvisory: https://osv.dev/vulnerability/GHSA-4x4j-2g7c-83w6\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-c7d443194adfb20e", "name": "Vulnerable dependency pillow 12.1.1: GHSA-5x94-69rx-g8h2", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-5x94-69rx-g8h2"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by GHSA-5x94-69rx-g8h2 (aka CVE-2026-54060).\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nPillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`\n\nAliases: BIT-pillow-2026-54060, CVE-2026-54060, PYSEC-2026-2254\nAdvisory: https://osv.dev/vulnerability/GHSA-5x94-69rx-g8h2\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-5f5f03af8b9e5f97", "name": "Vulnerable dependency pillow 12.1.1: GHSA-5xmw-vc9v-4wf2", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-5xmw-vc9v-4wf2"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by GHSA-5xmw-vc9v-4wf2 (aka CVE-2026-42309).\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nPillow has a heap buffer overflow with nested list coordinates\n\nAliases: BIT-pillow-2026-42309, CVE-2026-42309, PYSEC-2026-2251\nAdvisory: https://osv.dev/vulnerability/GHSA-5xmw-vc9v-4wf2\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-c90c2cc3242986d1", "name": "Vulnerable dependency pillow 12.1.1: GHSA-62p4-gmf7-7g93", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-62p4-gmf7-7g93"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by GHSA-62p4-gmf7-7g93 (aka CVE-2026-54058).\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nPillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)\n\nAliases: BIT-pillow-2026-54058, CVE-2026-54058, PYSEC-2026-3493\nAdvisory: https://osv.dev/vulnerability/GHSA-62p4-gmf7-7g93\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-b67d5225f870cc79", "name": "Vulnerable dependency pillow 12.1.1: GHSA-6r8x-57c9-28j4", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-6r8x-57c9-28j4"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by GHSA-6r8x-57c9-28j4.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6r8x-57c9-28j4\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-a6ffb483913324f2", "name": "Vulnerable dependency pillow 12.1.1: GHSA-8v84-f9pq-wr9x", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-8v84-f9pq-wr9x"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by GHSA-8v84-f9pq-wr9x.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8v84-f9pq-wr9x\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-ba9b4810598e0a86", "name": "Vulnerable dependency pillow 12.1.1: GHSA-9hw9-ch79-4vh6", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-9hw9-ch79-4vh6"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by GHSA-9hw9-ch79-4vh6.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9hw9-ch79-4vh6\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-5bd959f531adfcdb", "name": "Vulnerable dependency pillow 12.1.1: GHSA-fj7v-r99m-22gq", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-fj7v-r99m-22gq"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by GHSA-fj7v-r99m-22gq.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-fj7v-r99m-22gq\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-04e0686c4f897099", "name": "Vulnerable dependency pillow 12.1.1: GHSA-jjj6-mw9f-p565", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-jjj6-mw9f-p565"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by GHSA-jjj6-mw9f-p565.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jjj6-mw9f-p565\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-0b61d497510c1f45", "name": "Vulnerable dependency pillow 12.1.1: GHSA-pg7v-jwj7-p798", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-pg7v-jwj7-p798"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by GHSA-pg7v-jwj7-p798.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pg7v-jwj7-p798\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-d97c0d4e3887ff59", "name": "Vulnerable dependency pillow 12.1.1: GHSA-phj9-mv4w-65pm", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-phj9-mv4w-65pm"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by GHSA-phj9-mv4w-65pm.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-phj9-mv4w-65pm\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-fbe64b3bb98a7411", "name": "Vulnerable dependency pillow 12.1.1: GHSA-pwv6-vv43-88gr", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-pwv6-vv43-88gr"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by GHSA-pwv6-vv43-88gr.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pwv6-vv43-88gr\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-902035c4ddd9193c", "name": "Vulnerable dependency pillow 12.1.1: GHSA-r73j-pqj5-w3x7", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-r73j-pqj5-w3x7"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by GHSA-r73j-pqj5-w3x7.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r73j-pqj5-w3x7\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-7bd98520a60583dc", "name": "Vulnerable dependency pillow 12.1.1: GHSA-vjc4-5qp5-m44j", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-vjc4-5qp5-m44j"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by GHSA-vjc4-5qp5-m44j.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vjc4-5qp5-m44j\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-74d39e9c88f2e784", "name": "Vulnerable dependency pillow 12.1.1: GHSA-whj4-6x5x-4v2j", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-whj4-6x5x-4v2j"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by GHSA-whj4-6x5x-4v2j.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-whj4-6x5x-4v2j\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-681299b493aad42a", "name": "Vulnerable dependency pillow 12.1.1: GHSA-wjx4-4jcj-g98j", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-wjx4-4jcj-g98j"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by GHSA-wjx4-4jcj-g98j.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wjx4-4jcj-g98j\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-cbf499d877ebd15c", "name": "Vulnerable dependency pillow 12.1.1: GHSA-xj96-63gp-2gmr", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-xj96-63gp-2gmr"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by GHSA-xj96-63gp-2gmr.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xj96-63gp-2gmr\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-1ddcae6a88f7d119", "name": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-165", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-165"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by PYSEC-2026-165.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-165\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-65ae94d114639ce8", "name": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-2250", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-2250"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by PYSEC-2026-2250.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2250\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-e8e862ba3e0a1d52", "name": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-2252", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-2252"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by PYSEC-2026-2252.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2252\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-c0c2cd13aecc738c", "name": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-2253", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-2253"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by PYSEC-2026-2253.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2253\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-b8f5700978cfff89", "name": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-2256", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-2256"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by PYSEC-2026-2256.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2256\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-5d211138736351aa", "name": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-2874", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-2874"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by PYSEC-2026-2874.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2874\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-3bc3463012588ba5", "name": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-3451", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-3451"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by PYSEC-2026-3451.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3451\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-6fc9590ab689fec4", "name": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-3452", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-3452"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by PYSEC-2026-3452.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3452\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-05087a76da4ec480", "name": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-3453", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-3453"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by PYSEC-2026-3453.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3453\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-52514d835e9bfe9a", "name": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-3454", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-3454"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by PYSEC-2026-3454.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3454\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-563d1e13c71edb93", "name": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-3494", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-3494"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by PYSEC-2026-3494.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3494\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-4230330896223de4", "name": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-3495", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-3495"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by PYSEC-2026-3495.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3495\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-ac34956e395b775a", "name": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-3496", "shortDescription": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-3496"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.1.1` (resolved in `uv.lock`) is affected by PYSEC-2026-3496.\nNote: `pillow` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3496\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-4be8be837d3218a8", "name": "Vulnerable dependency pyasn1 0.6.3: GHSA-8ppf-4f7h-5ppj", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.3: GHSA-8ppf-4f7h-5ppj"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.3` (resolved in `uv.lock`) is affected by GHSA-8ppf-4f7h-5ppj.\nNote: `pyasn1` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8ppf-4f7h-5ppj\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-2a40b871965f1506", "name": "Vulnerable dependency pyasn1 0.6.3: GHSA-hm4w-wwcw-mr6r", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.3: GHSA-hm4w-wwcw-mr6r"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.3` (resolved in `uv.lock`) is affected by GHSA-hm4w-wwcw-mr6r.\nNote: `pyasn1` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hm4w-wwcw-mr6r\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-f8b7f5ba4fa43ada", "name": "Vulnerable dependency pyasn1 0.6.3: PYSEC-2026-3455", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.3: PYSEC-2026-3455"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.3` (resolved in `uv.lock`) is affected by PYSEC-2026-3455.\nNote: `pyasn1` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3455\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-8c025f6c1aee6ca0", "name": "Vulnerable dependency pyasn1 0.6.3: PYSEC-2026-3456", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.3: PYSEC-2026-3456"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.3` (resolved in `uv.lock`) is affected by PYSEC-2026-3456.\nNote: `pyasn1` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3456\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-9bbf32ae7157c304", "name": "Vulnerable dependency pyasn1 0.6.3: PYSEC-2026-3457", "shortDescription": {"text": "Vulnerable dependency pyasn1 0.6.3: PYSEC-2026-3457"}, "fullDescription": {"text": "OSV.dev reports `pyasn1` at version `0.6.3` (resolved in `uv.lock`) is affected by PYSEC-2026-3457.\nNote: `pyasn1` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3457\nFix: upgrade `pyasn1` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-561199607badef54", "name": "Vulnerable dependency pydantic-settings 2.13.1: GHSA-4xgf-cpjx-pc3j", "shortDescription": {"text": "Vulnerable dependency pydantic-settings 2.13.1: GHSA-4xgf-cpjx-pc3j"}, "fullDescription": {"text": "OSV.dev reports `pydantic-settings` at version `2.13.1` (resolved in `uv.lock`) is affected by GHSA-4xgf-cpjx-pc3j (aka CVE-2026-58203).\nNote: `pydantic-settings` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\npydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size\n\nAliases: CVE-2026-58203\nAdvisory: https://osv.dev/vulnerability/GHSA-4xgf-cpjx-pc3j\nFix: upgrade `pydantic-settings` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-2f35e24090839556", "name": "Vulnerable dependency pygments 2.19.2: GHSA-5239-wwwm-4pmq", "shortDescription": {"text": "Vulnerable dependency pygments 2.19.2: GHSA-5239-wwwm-4pmq"}, "fullDescription": {"text": "OSV.dev reports `pygments` at version `2.19.2` (resolved in `uv.lock`) is affected by GHSA-5239-wwwm-4pmq (aka CVE-2026-4539).\nNote: `pygments` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nPygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching\n\nAliases: CVE-2026-4539, PYSEC-2026-2987\nAdvisory: https://osv.dev/vulnerability/GHSA-5239-wwwm-4pmq\nFix: upgrade `pygments` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-15675fc0e6e4a478", "name": "Vulnerable dependency pyjwt 2.12.1: GHSA-993g-76c3-p5m4", "shortDescription": {"text": "Vulnerable dependency pyjwt 2.12.1: GHSA-993g-76c3-p5m4"}, "fullDescription": {"text": "OSV.dev reports `pyjwt` at version `2.12.1` (resolved in `uv.lock`) is affected by GHSA-993g-76c3-p5m4.\nNote: `pyjwt` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-993g-76c3-p5m4\nFix: upgrade `pyjwt` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-7c74016272c94101", "name": "Vulnerable dependency pyjwt 2.12.1: GHSA-fhv5-28vv-h8m8", "shortDescription": {"text": "Vulnerable dependency pyjwt 2.12.1: GHSA-fhv5-28vv-h8m8"}, "fullDescription": {"text": "OSV.dev reports `pyjwt` at version `2.12.1` (resolved in `uv.lock`) is affected by GHSA-fhv5-28vv-h8m8.\nNote: `pyjwt` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-fhv5-28vv-h8m8\nFix: upgrade `pyjwt` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-f4ff2ffc50e5625e", "name": "Vulnerable dependency pyjwt 2.12.1: GHSA-jq35-7prp-9v3f", "shortDescription": {"text": "Vulnerable dependency pyjwt 2.12.1: GHSA-jq35-7prp-9v3f"}, "fullDescription": {"text": "OSV.dev reports `pyjwt` at version `2.12.1` (resolved in `uv.lock`) is affected by GHSA-jq35-7prp-9v3f.\nNote: `pyjwt` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jq35-7prp-9v3f\nFix: upgrade `pyjwt` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-7220572de8863f14", "name": "Vulnerable dependency pyjwt 2.12.1: GHSA-w7vc-732c-9m39", "shortDescription": {"text": "Vulnerable dependency pyjwt 2.12.1: GHSA-w7vc-732c-9m39"}, "fullDescription": {"text": "OSV.dev reports `pyjwt` at version `2.12.1` (resolved in `uv.lock`) is affected by GHSA-w7vc-732c-9m39.\nNote: `pyjwt` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w7vc-732c-9m39\nFix: upgrade `pyjwt` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-a663ffba8e01f884", "name": "Vulnerable dependency pyjwt 2.12.1: GHSA-xgmm-8j9v-c9wx", "shortDescription": {"text": "Vulnerable dependency pyjwt 2.12.1: GHSA-xgmm-8j9v-c9wx"}, "fullDescription": {"text": "OSV.dev reports `pyjwt` at version `2.12.1` (resolved in `uv.lock`) is affected by GHSA-xgmm-8j9v-c9wx.\nNote: `pyjwt` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xgmm-8j9v-c9wx\nFix: upgrade `pyjwt` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-7d880cf256dd06b6", "name": "Vulnerable dependency pyjwt 2.12.1: PYSEC-2026-175", "shortDescription": {"text": "Vulnerable dependency pyjwt 2.12.1: PYSEC-2026-175"}, "fullDescription": {"text": "OSV.dev reports `pyjwt` at version `2.12.1` (resolved in `uv.lock`) is affected by PYSEC-2026-175.\nNote: `pyjwt` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-175\nFix: upgrade `pyjwt` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-306b94bda0170a97", "name": "Vulnerable dependency pyjwt 2.12.1: PYSEC-2026-177", "shortDescription": {"text": "Vulnerable dependency pyjwt 2.12.1: PYSEC-2026-177"}, "fullDescription": {"text": "OSV.dev reports `pyjwt` at version `2.12.1` (resolved in `uv.lock`) is affected by PYSEC-2026-177.\nNote: `pyjwt` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-177\nFix: upgrade `pyjwt` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-954ab89c5884c7e6", "name": "Vulnerable dependency pyjwt 2.12.1: PYSEC-2026-178", "shortDescription": {"text": "Vulnerable dependency pyjwt 2.12.1: PYSEC-2026-178"}, "fullDescription": {"text": "OSV.dev reports `pyjwt` at version `2.12.1` (resolved in `uv.lock`) is affected by PYSEC-2026-178.\nNote: `pyjwt` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-178\nFix: upgrade `pyjwt` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-ef485dff6a0b4b22", "name": "Vulnerable dependency pyjwt 2.12.1: PYSEC-2026-179", "shortDescription": {"text": "Vulnerable dependency pyjwt 2.12.1: PYSEC-2026-179"}, "fullDescription": {"text": "OSV.dev reports `pyjwt` at version `2.12.1` (resolved in `uv.lock`) is affected by PYSEC-2026-179.\nNote: `pyjwt` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-179\nFix: upgrade `pyjwt` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-f4b15ef3314d46dd", "name": "Vulnerable dependency python-multipart 0.0.22: GHSA-5rvq-cxj2-64vf", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-5rvq-cxj2-64vf"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `uv.lock`) is affected by GHSA-5rvq-cxj2-64vf (aka CVE-2026-53539).\nNote: `python-multipart` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\npython-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service\n\nAliases: CVE-2026-53539, PYSEC-2026-3036\nAdvisory: https://osv.dev/vulnerability/GHSA-5rvq-cxj2-64vf\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-a234e701f1591250", "name": "Vulnerable dependency python-multipart 0.0.22: GHSA-6jv3-5f52-599m", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-6jv3-5f52-599m"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `uv.lock`) is affected by GHSA-6jv3-5f52-599m.\nNote: `python-multipart` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6jv3-5f52-599m\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-f071086931bc6bf3", "name": "Vulnerable dependency python-multipart 0.0.22: GHSA-mj87-hwqh-73pj", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-mj87-hwqh-73pj"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `uv.lock`) is affected by GHSA-mj87-hwqh-73pj.\nNote: `python-multipart` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mj87-hwqh-73pj\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-14d1ea28365214f4", "name": "Vulnerable dependency python-multipart 0.0.22: GHSA-pp6c-gr5w-3c5g", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-pp6c-gr5w-3c5g"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `uv.lock`) is affected by GHSA-pp6c-gr5w-3c5g.\nNote: `python-multipart` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pp6c-gr5w-3c5g\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-50238634a6e27df0", "name": "Vulnerable dependency python-multipart 0.0.22: GHSA-v9pg-7xvm-68hf", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-v9pg-7xvm-68hf"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `uv.lock`) is affected by GHSA-v9pg-7xvm-68hf.\nNote: `python-multipart` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v9pg-7xvm-68hf\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-ce264103618eff28", "name": "Vulnerable dependency python-multipart 0.0.22: GHSA-vffw-93wf-4j4q", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-vffw-93wf-4j4q"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `uv.lock`) is affected by GHSA-vffw-93wf-4j4q.\nNote: `python-multipart` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vffw-93wf-4j4q\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-675e8fad05133489", "name": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3037", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3037"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `uv.lock`) is affected by PYSEC-2026-3037.\nNote: `python-multipart` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3037\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-5a8001ff392d339c", "name": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3038", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3038"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `uv.lock`) is affected by PYSEC-2026-3038.\nNote: `python-multipart` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3038\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-87057aa9b7c3dfe7", "name": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3039", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3039"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `uv.lock`) is affected by PYSEC-2026-3039.\nNote: `python-multipart` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3039\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-727fff841f1fca00", "name": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3040", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3040"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `uv.lock`) is affected by PYSEC-2026-3040.\nNote: `python-multipart` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3040\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-df64a46023050a34", "name": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3041", "shortDescription": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3041"}, "fullDescription": {"text": "OSV.dev reports `python-multipart` at version `0.0.22` (resolved in `uv.lock`) is affected by PYSEC-2026-3041.\nNote: `python-multipart` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3041\nFix: upgrade `python-multipart` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-8da0231e5842f2d7", "name": "Vulnerable dependency requests 2.32.5: GHSA-gc5v-m9x4-r6x2", "shortDescription": {"text": "Vulnerable dependency requests 2.32.5: GHSA-gc5v-m9x4-r6x2"}, "fullDescription": {"text": "OSV.dev reports `requests` at version `2.32.5` (resolved in `uv.lock`) is affected by GHSA-gc5v-m9x4-r6x2.\nNote: `requests` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-gc5v-m9x4-r6x2\nFix: upgrade `requests` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-fb139b5396a6b198", "name": "Vulnerable dependency requests 2.32.5: PYSEC-2026-2275", "shortDescription": {"text": "Vulnerable dependency requests 2.32.5: PYSEC-2026-2275"}, "fullDescription": {"text": "OSV.dev reports `requests` at version `2.32.5` (resolved in `uv.lock`) is affected by PYSEC-2026-2275.\nNote: `requests` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2275\nFix: upgrade `requests` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-02beaef6201fc578", "name": "Vulnerable dependency setuptools 82.0.1: GHSA-h35f-9h28-mq5c", "shortDescription": {"text": "Vulnerable dependency setuptools 82.0.1: GHSA-h35f-9h28-mq5c"}, "fullDescription": {"text": "OSV.dev reports `setuptools` at version `82.0.1` (resolved in `uv.lock`) is affected by GHSA-h35f-9h28-mq5c.\nNote: `setuptools` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-h35f-9h28-mq5c\nFix: upgrade `setuptools` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-128492a85849709f", "name": "Vulnerable dependency setuptools 82.0.1: PYSEC-2026-3447", "shortDescription": {"text": "Vulnerable dependency setuptools 82.0.1: PYSEC-2026-3447"}, "fullDescription": {"text": "OSV.dev reports `setuptools` at version `82.0.1` (resolved in `uv.lock`) is affected by PYSEC-2026-3447.\nNote: `setuptools` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3447\nFix: upgrade `setuptools` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-f2c8013eb5eaff91", "name": "Vulnerable dependency starlette 0.52.1: GHSA-82w8-qh3p-5jfq", "shortDescription": {"text": "Vulnerable dependency starlette 0.52.1: GHSA-82w8-qh3p-5jfq"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.52.1` (resolved in `uv.lock`) is affected by GHSA-82w8-qh3p-5jfq.\nNote: `starlette` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-82w8-qh3p-5jfq\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-5c15b30fde69ed75", "name": "Vulnerable dependency starlette 0.52.1: GHSA-86qp-5c8j-p5mr", "shortDescription": {"text": "Vulnerable dependency starlette 0.52.1: GHSA-86qp-5c8j-p5mr"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.52.1` (resolved in `uv.lock`) is affected by GHSA-86qp-5c8j-p5mr.\nNote: `starlette` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-86qp-5c8j-p5mr\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-68d456f086a60172", "name": "Vulnerable dependency starlette 0.52.1: GHSA-jp82-jpqv-5vv3", "shortDescription": {"text": "Vulnerable dependency starlette 0.52.1: GHSA-jp82-jpqv-5vv3"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.52.1` (resolved in `uv.lock`) is affected by GHSA-jp82-jpqv-5vv3.\nNote: `starlette` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jp82-jpqv-5vv3\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-fc8f5ac9a4f33f8f", "name": "Vulnerable dependency starlette 0.52.1: GHSA-wqp7-x3pw-xc5r", "shortDescription": {"text": "Vulnerable dependency starlette 0.52.1: GHSA-wqp7-x3pw-xc5r"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.52.1` (resolved in `uv.lock`) is affected by GHSA-wqp7-x3pw-xc5r.\nNote: `starlette` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wqp7-x3pw-xc5r\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-7da100bb44b705f7", "name": "Vulnerable dependency starlette 0.52.1: GHSA-x746-7m8f-x49c", "shortDescription": {"text": "Vulnerable dependency starlette 0.52.1: GHSA-x746-7m8f-x49c"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.52.1` (resolved in `uv.lock`) is affected by GHSA-x746-7m8f-x49c.\nNote: `starlette` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-x746-7m8f-x49c\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-d045151a0b52dfbd", "name": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-161", "shortDescription": {"text": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-161"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.52.1` (resolved in `uv.lock`) is affected by PYSEC-2026-161.\nNote: `starlette` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-161\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-db597718539d655b", "name": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-2280", "shortDescription": {"text": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-2280"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.52.1` (resolved in `uv.lock`) is affected by PYSEC-2026-2280.\nNote: `starlette` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2280\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-526a1dd33e27d6f5", "name": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-2281", "shortDescription": {"text": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-2281"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.52.1` (resolved in `uv.lock`) is affected by PYSEC-2026-2281.\nNote: `starlette` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2281\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-28608c156a1a234a", "name": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-248", "shortDescription": {"text": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-248"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.52.1` (resolved in `uv.lock`) is affected by PYSEC-2026-248.\nNote: `starlette` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-248\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-8ce24ff16c98d6d5", "name": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-249", "shortDescription": {"text": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-249"}, "fullDescription": {"text": "OSV.dev reports `starlette` at version `0.52.1` (resolved in `uv.lock`) is affected by PYSEC-2026-249.\nNote: `starlette` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-249\nFix: upgrade `starlette` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-598c14bfc13989e2", "name": "Vulnerable dependency torch 2.10.0: GHSA-rrmf-rvhw-rf47", "shortDescription": {"text": "Vulnerable dependency torch 2.10.0: GHSA-rrmf-rvhw-rf47"}, "fullDescription": {"text": "OSV.dev reports `torch` at version `2.10.0` (resolved in `uv.lock`) is affected by GHSA-rrmf-rvhw-rf47.\nNote: `torch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rrmf-rvhw-rf47\nFix: upgrade `torch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-cd035c134e2bfaa7", "name": "Vulnerable dependency torch 2.10.0: PYSEC-2026-139", "shortDescription": {"text": "Vulnerable dependency torch 2.10.0: PYSEC-2026-139"}, "fullDescription": {"text": "OSV.dev reports `torch` at version `2.10.0` (resolved in `uv.lock`) is affected by PYSEC-2026-139.\nNote: `torch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-139\nFix: upgrade `torch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-f11679ab31b87155", "name": "Vulnerable dependency transformers 4.57.6: GHSA-29pf-2h5f-8g72", "shortDescription": {"text": "Vulnerable dependency transformers 4.57.6: GHSA-29pf-2h5f-8g72"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.57.6` (resolved in `uv.lock`) is affected by GHSA-29pf-2h5f-8g72 (aka CVE-2026-4372).\nNote: `transformers` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nHuggingFace transformers vulnerable to remote code execution\n\nAliases: CVE-2026-4372, PYSEC-2026-2289\nAdvisory: https://osv.dev/vulnerability/GHSA-29pf-2h5f-8g72\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-ca4664d7ef14cfd9", "name": "Vulnerable dependency transformers 4.57.6: GHSA-69w3-r845-3855", "shortDescription": {"text": "Vulnerable dependency transformers 4.57.6: GHSA-69w3-r845-3855"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.57.6` (resolved in `uv.lock`) is affected by GHSA-69w3-r845-3855 (aka CVE-2026-1839).\nNote: `transformers` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nHuggingFace Transformers allows for arbitrary code execution in the `Trainer` class\n\nAliases: CVE-2026-1839, PYSEC-2026-2288\nAdvisory: https://osv.dev/vulnerability/GHSA-69w3-r845-3855\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-ceebb417c6ccd532", "name": "Vulnerable dependency transformers 4.57.6: GHSA-fgcw-684q-jj6r", "shortDescription": {"text": "Vulnerable dependency transformers 4.57.6: GHSA-fgcw-684q-jj6r"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.57.6` (resolved in `uv.lock`) is affected by GHSA-fgcw-684q-jj6r.\nNote: `transformers` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-fgcw-684q-jj6r\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-0cab1e5833db8f05", "name": "Vulnerable dependency transformers 4.57.6: PYSEC-2025-217", "shortDescription": {"text": "Vulnerable dependency transformers 4.57.6: PYSEC-2025-217"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.57.6` (resolved in `uv.lock`) is affected by PYSEC-2025-217.\nNote: `transformers` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2025-217\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-11d3f0e737cf8fe9", "name": "Vulnerable dependency transformers 4.57.6: PYSEC-2026-2290", "shortDescription": {"text": "Vulnerable dependency transformers 4.57.6: PYSEC-2026-2290"}, "fullDescription": {"text": "OSV.dev reports `transformers` at version `4.57.6` (resolved in `uv.lock`) is affected by PYSEC-2026-2290.\nNote: `transformers` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2290\nFix: upgrade `transformers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-47cc8878f0379db8", "name": "Vulnerable dependency urllib3 2.6.3: GHSA-mf9v-mfxr-j63j", "shortDescription": {"text": "Vulnerable dependency urllib3 2.6.3: GHSA-mf9v-mfxr-j63j"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.6.3` (resolved in `uv.lock`) is affected by GHSA-mf9v-mfxr-j63j.\nNote: `urllib3` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mf9v-mfxr-j63j\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-433f57b90f387132", "name": "Vulnerable dependency urllib3 2.6.3: GHSA-qccp-gfcp-xxvc", "shortDescription": {"text": "Vulnerable dependency urllib3 2.6.3: GHSA-qccp-gfcp-xxvc"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.6.3` (resolved in `uv.lock`) is affected by GHSA-qccp-gfcp-xxvc.\nNote: `urllib3` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qccp-gfcp-xxvc\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-9a7d4ee40fdfda62", "name": "Vulnerable dependency urllib3 2.6.3: PYSEC-2026-141", "shortDescription": {"text": "Vulnerable dependency urllib3 2.6.3: PYSEC-2026-141"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.6.3` (resolved in `uv.lock`) is affected by PYSEC-2026-141.\nNote: `urllib3` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-141\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-b0cc2808acdb73ab", "name": "Vulnerable dependency urllib3 2.6.3: PYSEC-2026-142", "shortDescription": {"text": "Vulnerable dependency urllib3 2.6.3: PYSEC-2026-142"}, "fullDescription": {"text": "OSV.dev reports `urllib3` at version `2.6.3` (resolved in `uv.lock`) is affected by PYSEC-2026-142.\nNote: `urllib3` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-142\nFix: upgrade `urllib3` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-718339b057a5c1f3", "name": "Dependency better-sqlite3 is a major version behind", "shortDescription": {"text": "Dependency better-sqlite3 is a major version behind"}, "fullDescription": {"text": "`better-sqlite3` is pinned at `12.4.1` in `code-review-graph-vscode/package.json` while the latest release on the npm registry is `13.0.1` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `better-sqlite3` to `13.0.1`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}]}}, "automationDetails": {"id": "repobility/30740"}, "properties": {"repository": "tirth8205/code-review-graph", "repoUrl": "https://github.com/tirth8205/code-review-graph", "branch": "main"}, "results": [{"ruleId": "scanner-1ed8f25aa5b9b00d", "level": "note", "message": {"text": "Possibly dead Python function: d1"}, "properties": {"repobilityId": "8f624459a69480eb", "scanner": "scanner-primary", "fingerprint": "1ed8f25aa5b9b00d", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "diagrams/generate_diagrams.py:108"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9cfdb1a3b5cbf60a", "level": "note", "message": {"text": "Possibly dead Python function: d2"}, "properties": {"repobilityId": "1298ca9784200e7d", "scanner": "scanner-primary", "fingerprint": "9cfdb1a3b5cbf60a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "diagrams/generate_diagrams.py:199"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-713b48b06724c3de", "level": "note", "message": {"text": "Possibly dead Python function: d3"}, "properties": {"repobilityId": "20cb1119ffb34c76", "scanner": "scanner-primary", "fingerprint": "713b48b06724c3de", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "diagrams/generate_diagrams.py:239"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bcc72456aa4ba790", "level": "note", "message": {"text": "Possibly dead Python function: d4"}, "properties": {"repobilityId": "98d6382351abf1e1", "scanner": "scanner-primary", "fingerprint": "bcc72456aa4ba790", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "diagrams/generate_diagrams.py:334"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cd30640c975805e8", "level": "note", "message": {"text": "Possibly dead Python function: d5"}, "properties": {"repobilityId": "2c41340d5a3db9fb", "scanner": "scanner-primary", "fingerprint": "cd30640c975805e8", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "diagrams/generate_diagrams.py:400"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2629c48467d7bda8", "level": "note", "message": {"text": "Possibly dead Python function: d6"}, "properties": {"repobilityId": "0661de6ca6a9ce9c", "scanner": "scanner-primary", "fingerprint": "2629c48467d7bda8", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "diagrams/generate_diagrams.py:451"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6920b7b65d7d9aff", "level": "note", "message": {"text": "Possibly dead Python function: d7"}, "properties": {"repobilityId": "8b6eda72ab51f8b7", "scanner": "scanner-primary", "fingerprint": "6920b7b65d7d9aff", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "diagrams/generate_diagrams.py:515"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e76243c48deac2f6", "level": "note", "message": {"text": "Possibly dead Python function: d8"}, "properties": {"repobilityId": "09fa751409b511f4", "scanner": "scanner-primary", "fingerprint": "e76243c48deac2f6", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "diagrams/generate_diagrams.py:586"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c18aa64ba0479754", "level": "note", "message": {"text": "Possibly dead Python function: d9"}, "properties": {"repobilityId": "759caf37a3e4318f", "scanner": "scanner-primary", "fingerprint": "c18aa64ba0479754", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "diagrams/generate_diagrams.py:661"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a59bf70c31bc9138", "level": "note", "message": {"text": "Possibly dead Python function: run_token_benchmark"}, "properties": {"repobilityId": "0dab77d49c6aa02b", "scanner": "scanner-primary", "fingerprint": "a59bf70c31bc9138", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/token_benchmark.py:48"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bf68f65548b1e7b0", "level": "note", "message": {"text": "Possibly dead Python function: visit_Name"}, "properties": {"repobilityId": "c16c7f6e311e5eb3", "scanner": "scanner-primary", "fingerprint": "bf68f65548b1e7b0", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/parser.py:93"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2a68cb1c2f33de0a", "level": "note", "message": {"text": "Possibly dead Python function: visit_FunctionDef"}, "properties": {"repobilityId": "7a354842f176b228", "scanner": "scanner-primary", "fingerprint": "2a68cb1c2f33de0a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/parser.py:223"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-800b78ca5e3e6901", "level": "note", "message": {"text": "Possibly dead Python function: visit_AsyncFunctionDef"}, "properties": {"repobilityId": "eac17513dd240cf3", "scanner": "scanner-primary", "fingerprint": "800b78ca5e3e6901", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/parser.py:226"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-756b916f8687c4e8", "level": "note", "message": {"text": "Possibly dead Python function: visit_ClassDef"}, "properties": {"repobilityId": "4ddb6420f5455a47", "scanner": "scanner-primary", "fingerprint": "756b916f8687c4e8", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/parser.py:232"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d68334e9565bc97b", "level": "note", "message": {"text": "Possibly dead Python function: visit_Lambda"}, "properties": {"repobilityId": "e414da02f3901eb2", "scanner": "scanner-primary", "fingerprint": "d68334e9565bc97b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/parser.py:109"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cacee80b7dab05f6", "level": "note", "message": {"text": "Possibly dead Python function: visit_Import"}, "properties": {"repobilityId": "66cd6a2eba488b69", "scanner": "scanner-primary", "fingerprint": "cacee80b7dab05f6", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/parser.py:112"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7eba5afb1fa27168", "level": "note", "message": {"text": "Possibly dead Python function: visit_ImportFrom"}, "properties": {"repobilityId": "9943a88b95a56d70", "scanner": "scanner-primary", "fingerprint": "7eba5afb1fa27168", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/parser.py:116"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-51273acd6d86664e", "level": "note", "message": {"text": "Possibly dead Python function: visit_Call"}, "properties": {"repobilityId": "83d516a32f6d02f1", "scanner": "scanner-primary", "fingerprint": "51273acd6d86664e", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/parser.py:208"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-953a637314df4f26", "level": "note", "message": {"text": "Possibly dead Python function: visit_If"}, "properties": {"repobilityId": "553331d7d151e6cd", "scanner": "scanner-primary", "fingerprint": "953a637314df4f26", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/parser.py:213"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-104ca6ed3d607bc4", "level": "note", "message": {"text": "Possibly dead Python function: replace_comment"}, "properties": {"repobilityId": "2ff2d0145bd05ae0", "scanner": "scanner-primary", "fingerprint": "104ca6ed3d607bc4", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/parser.py:2405"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ea0fd0d3cedec28", "level": "note", "message": {"text": "Possibly dead Python function: save_result"}, "properties": {"repobilityId": "a77e1157335e2626", "scanner": "scanner-primary", "fingerprint": "3ea0fd0d3cedec28", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/memory.py:14"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-64efa2328e296640", "level": "note", "message": {"text": "Possibly dead Python function: list_memories"}, "properties": {"repobilityId": "c1c2d734bee072a1", "scanner": "scanner-primary", "fingerprint": "64efa2328e296640", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/memory.py:77"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-87b12cc600270924", "level": "note", "message": {"text": "Possibly dead Python function: clear_memories"}, "properties": {"repobilityId": "1726b0c1a57f752e", "scanner": "scanner-primary", "fingerprint": "87b12cc600270924", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/memory.py:121"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b4844f191a964731", "level": "note", "message": {"text": "Possibly dead Python function: enrich_jedi_calls"}, "properties": {"repobilityId": "372b0c0a295d0a34", "scanner": "scanner-primary", "fingerprint": "b4844f191a964731", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/jedi_resolver.py:27"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-39bcf1408de604d7", "level": "note", "message": {"text": "Possibly dead Python function: take_snapshot"}, "properties": {"repobilityId": "c23011bc08cd04ba", "scanner": "scanner-primary", "fingerprint": "39bcf1408de604d7", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/graph_diff.py:15"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c076c779faec8e6b", "level": "note", "message": {"text": "Possibly dead Python function: save_snapshot"}, "properties": {"repobilityId": "d3f54754f57830be", "scanner": "scanner-primary", "fingerprint": "c076c779faec8e6b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/graph_diff.py:46"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5e2471b34306193a", "level": "note", "message": {"text": "Possibly dead Python function: load_snapshot"}, "properties": {"repobilityId": "5139d5c11f0e9533", "scanner": "scanner-primary", "fingerprint": "5e2471b34306193a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/graph_diff.py:56"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c54a975ea224fef3", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 code_review_graph/embeddings.py:293"}, "properties": {"repobilityId": "431c3b1abe096df7", "scanner": "scanner-primary", "fingerprint": "c54a975ea224fef3", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/embeddings.py"}, "region": {"startLine": 293}}}]}, {"ruleId": "scanner-541694fb0e092f8c", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 scripts/diagnose_pypi_connectivity.py:54"}, "properties": {"repobilityId": "cfc66d30d3d9de06", "scanner": "scanner-primary", "fingerprint": "541694fb0e092f8c", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/diagnose_pypi_connectivity.py"}, "region": {"startLine": 54}}}]}, {"ruleId": "scanner-fd0f8adede1539b2", "level": "warning", "message": {"text": "CVE-2026-41425: authlib 1.6.9 \u2014 uv.lock"}, "properties": {"repobilityId": "bd82b013226bd68e", "scanner": "scanner-primary", "fingerprint": "fd0f8adede1539b2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41425"]}}, {"ruleId": "scanner-61be9d0ebae5f57b", "level": "warning", "message": {"text": "CVE-2026-41479: authlib 1.6.9 \u2014 uv.lock"}, "properties": {"repobilityId": "16fb3c11745eec82", "scanner": "scanner-primary", "fingerprint": "61be9d0ebae5f57b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41479"]}}, {"ruleId": "scanner-81247f3ad8f53a65", "level": "warning", "message": {"text": "CVE-2026-44681: authlib 1.6.9 \u2014 uv.lock"}, "properties": {"repobilityId": "cb4850a90722fd1c", "scanner": "scanner-primary", "fingerprint": "81247f3ad8f53a65", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44681"]}}, {"ruleId": "scanner-c5336b6cde629f40", "level": "error", "message": {"text": "GHSA-537c-gmf6-5ccf: cryptography 46.0.5 \u2014 uv.lock"}, "properties": {"repobilityId": "a6d76544a3204701", "scanner": "scanner-primary", "fingerprint": "c5336b6cde629f40", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-537c-gmf6-5ccf"]}}, {"ruleId": "scanner-cd5d9fc326eb90c0", "level": "warning", "message": {"text": "CVE-2026-39892: cryptography 46.0.5 \u2014 uv.lock"}, "properties": {"repobilityId": "5bdcf27af4f6891e", "scanner": "scanner-primary", "fingerprint": "cd5d9fc326eb90c0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39892"]}}, {"ruleId": "scanner-b5735cdb2841320d", "level": "note", "message": {"text": "CVE-2026-34073: cryptography 46.0.5 \u2014 uv.lock"}, "properties": {"repobilityId": "5f0617f1e8bff253", "scanner": "scanner-primary", "fingerprint": "b5735cdb2841320d", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34073"]}}, {"ruleId": "scanner-206a6aeb11dedddf", "level": "warning", "message": {"text": "CVE-2026-45409: idna 3.11 \u2014 uv.lock"}, "properties": {"repobilityId": "c2f0a4d128834c6b", "scanner": "scanner-primary", "fingerprint": "206a6aeb11dedddf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45409"]}}, {"ruleId": "scanner-e8d6ba8517d23e72", "level": "error", "message": {"text": "CVE-2026-52869: mcp 1.26.0 \u2014 uv.lock"}, "properties": {"repobilityId": "1c41447db45d918e", "scanner": "scanner-primary", "fingerprint": "e8d6ba8517d23e72", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-52869"]}}, {"ruleId": "scanner-feb597e31f9086f4", "level": "error", "message": {"text": "CVE-2026-52870: mcp 1.26.0 \u2014 uv.lock"}, "properties": {"repobilityId": "542b0ca2f52ed8fe", "scanner": "scanner-primary", "fingerprint": "feb597e31f9086f4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-52870"]}}, {"ruleId": "scanner-ed443779d57d0e98", "level": "error", "message": {"text": "CVE-2026-59950: mcp 1.26.0 \u2014 uv.lock"}, "properties": {"repobilityId": "72bb20114a795fd4", "scanner": "scanner-primary", "fingerprint": "ed443779d57d0e98", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59950"]}}, {"ruleId": "scanner-ca8bfe770072a982", "level": "error", "message": {"text": "CVE-2026-40192: pillow 12.1.1 \u2014 uv.lock"}, "properties": {"repobilityId": "17bb3e9b7f9a6514", "scanner": "scanner-primary", "fingerprint": "ca8bfe770072a982", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40192"]}}, {"ruleId": "scanner-d2adf6cae79bd898", "level": "error", "message": {"text": "CVE-2026-42311: pillow 12.1.1 \u2014 uv.lock"}, "properties": {"repobilityId": "c3ecdb07a2114f54", "scanner": "scanner-primary", "fingerprint": "d2adf6cae79bd898", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42311"]}}, {"ruleId": "scanner-7be7393337ad7e9b", "level": "error", "message": {"text": "CVE-2026-54058: pillow 12.1.1 \u2014 uv.lock"}, "properties": {"repobilityId": "ad6b9031837af19d", "scanner": "scanner-primary", "fingerprint": "7be7393337ad7e9b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54058"]}}, {"ruleId": "scanner-724a69f7397f494c", "level": "error", "message": {"text": "CVE-2026-54059: pillow 12.1.1 \u2014 uv.lock"}, "properties": {"repobilityId": "4fd6401261d7b673", "scanner": "scanner-primary", "fingerprint": "724a69f7397f494c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54059"]}}, {"ruleId": "scanner-b3734dc4c7bb827e", "level": "error", "message": {"text": "CVE-2026-54060: pillow 12.1.1 \u2014 uv.lock"}, "properties": {"repobilityId": "460c3dd8de6beb2a", "scanner": "scanner-primary", "fingerprint": "b3734dc4c7bb827e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54060"]}}, {"ruleId": "scanner-0b87306fb2726d2c", "level": "error", "message": {"text": "CVE-2026-55379: pillow 12.1.1 \u2014 uv.lock"}, "properties": {"repobilityId": "41cc2c5cfa0ab3e7", "scanner": "scanner-primary", "fingerprint": "0b87306fb2726d2c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55379"]}}, {"ruleId": "scanner-f05f5f8299ab3a19", "level": "error", "message": {"text": "CVE-2026-55380: pillow 12.1.1 \u2014 uv.lock"}, "properties": {"repobilityId": "f90615a9989f57bc", "scanner": "scanner-primary", "fingerprint": "f05f5f8299ab3a19", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55380"]}}, {"ruleId": "scanner-06d1552b59366417", "level": "error", "message": {"text": "CVE-2026-59197: pillow 12.1.1 \u2014 uv.lock"}, "properties": {"repobilityId": "b4fa5d22b574d8f3", "scanner": "scanner-primary", "fingerprint": "06d1552b59366417", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59197"]}}, {"ruleId": "scanner-bf3b5ec880438ff5", "level": "error", "message": {"text": "CVE-2026-59199: pillow 12.1.1 \u2014 uv.lock"}, "properties": {"repobilityId": "1c3986517b685ff4", "scanner": "scanner-primary", "fingerprint": "bf3b5ec880438ff5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59199"]}}, {"ruleId": "scanner-19e738452d3cd1d7", "level": "error", "message": {"text": "CVE-2026-59200: pillow 12.1.1 \u2014 uv.lock"}, "properties": {"repobilityId": "278253220173941f", "scanner": "scanner-primary", "fingerprint": "19e738452d3cd1d7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59200"]}}, {"ruleId": "scanner-93510f1b6a5261e0", "level": "error", "message": {"text": "CVE-2026-59204: pillow 12.1.1 \u2014 uv.lock"}, "properties": {"repobilityId": "ad08bb4154b8a7b2", "scanner": "scanner-primary", "fingerprint": "93510f1b6a5261e0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59204"]}}, {"ruleId": "scanner-0e7e5b47ca3900a4", "level": "error", "message": {"text": "CVE-2026-59205: pillow 12.1.1 \u2014 uv.lock"}, "properties": {"repobilityId": "cc9b1626466d8587", "scanner": "scanner-primary", "fingerprint": "0e7e5b47ca3900a4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59205"]}}, {"ruleId": "scanner-c1627f08bd158383", "level": "warning", "message": {"text": "CVE-2026-42308: pillow 12.1.1 \u2014 uv.lock"}, "properties": {"repobilityId": "1792d2d9e870c1d3", "scanner": "scanner-primary", "fingerprint": "c1627f08bd158383", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42308"]}}, {"ruleId": "scanner-0196d8d5c8df830b", "level": "warning", "message": {"text": "CVE-2026-42309: pillow 12.1.1 \u2014 uv.lock"}, "properties": {"repobilityId": "0bdeb519d4de6638", "scanner": "scanner-primary", "fingerprint": "0196d8d5c8df830b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42309"]}}, {"ruleId": "scanner-adeed4fa8413bca9", "level": "warning", "message": {"text": "CVE-2026-42310: pillow 12.1.1 \u2014 uv.lock"}, "properties": {"repobilityId": "4b1952d1b96a5fa0", "scanner": "scanner-primary", "fingerprint": "adeed4fa8413bca9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42310"]}}, {"ruleId": "scanner-e28c8f1a94d496aa", "level": "warning", "message": {"text": "CVE-2026-55798: pillow 12.1.1 \u2014 uv.lock"}, "properties": {"repobilityId": "d0d151cc4785c963", "scanner": "scanner-primary", "fingerprint": "e28c8f1a94d496aa", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55798"]}}, {"ruleId": "scanner-3559b73b16add84c", "level": "warning", "message": {"text": "CVE-2026-59198: pillow 12.1.1 \u2014 uv.lock"}, "properties": {"repobilityId": "4b734d961778b7aa", "scanner": "scanner-primary", "fingerprint": "3559b73b16add84c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59198"]}}, {"ruleId": "scanner-0723c1ef2398e321", "level": "warning", "message": {"text": "CVE-2026-59203: pillow 12.1.1 \u2014 uv.lock"}, "properties": {"repobilityId": "23f54ff1326a45d7", "scanner": "scanner-primary", "fingerprint": "0723c1ef2398e321", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59203"]}}, {"ruleId": "scanner-0bf4b6732214b3f2", "level": "error", "message": {"text": "CVE-2026-59885: pyasn1 0.6.3 \u2014 uv.lock"}, "properties": {"repobilityId": "01feb8e00c6b8d6d", "scanner": "scanner-primary", "fingerprint": "0bf4b6732214b3f2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59885"]}}, {"ruleId": "scanner-988094facb9cf24b", "level": "error", "message": {"text": "CVE-2026-59886: pyasn1 0.6.3 \u2014 uv.lock"}, "properties": {"repobilityId": "f14e1a039e252f5b", "scanner": "scanner-primary", "fingerprint": "988094facb9cf24b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59886"]}}, {"ruleId": "scanner-2c9f940291de2b45", "level": "warning", "message": {"text": "GHSA-4xgf-cpjx-pc3j: pydantic-settings 2.13.1 \u2014 uv.lock"}, "properties": {"repobilityId": "c882a46b2faaf478", "scanner": "scanner-primary", "fingerprint": "2c9f940291de2b45", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-4xgf-cpjx-pc3j"]}}, {"ruleId": "scanner-0da8a15114591082", "level": "note", "message": {"text": "CVE-2026-4539: pygments 2.19.2 \u2014 uv.lock"}, "properties": {"repobilityId": "f9fcbb5336951446", "scanner": "scanner-primary", "fingerprint": "0da8a15114591082", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4539"]}}, {"ruleId": "scanner-6514fbdcfaa9204b", "level": "error", "message": {"text": "CVE-2026-48526: pyjwt 2.12.1 \u2014 uv.lock"}, "properties": {"repobilityId": "5c15467f51394509", "scanner": "scanner-primary", "fingerprint": "6514fbdcfaa9204b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48526"]}}, {"ruleId": "scanner-10d45d6df7a6f197", "level": "warning", "message": {"text": "CVE-2026-48522: pyjwt 2.12.1 \u2014 uv.lock"}, "properties": {"repobilityId": "398f7c0886f6723a", "scanner": "scanner-primary", "fingerprint": "10d45d6df7a6f197", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48522"]}}, {"ruleId": "scanner-5728cdec0dc11919", "level": "warning", "message": {"text": "CVE-2026-48523: pyjwt 2.12.1 \u2014 uv.lock"}, "properties": {"repobilityId": "626f80e71164bc6f", "scanner": "scanner-primary", "fingerprint": "5728cdec0dc11919", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48523"]}}, {"ruleId": "scanner-4ba6012c73817cff", "level": "warning", "message": {"text": "CVE-2026-48525: pyjwt 2.12.1 \u2014 uv.lock"}, "properties": {"repobilityId": "ac36236fcc88958d", "scanner": "scanner-primary", "fingerprint": "4ba6012c73817cff", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48525"]}}, {"ruleId": "scanner-898e5e1bfb2fa7db", "level": "note", "message": {"text": "CVE-2026-48524: pyjwt 2.12.1 \u2014 uv.lock"}, "properties": {"repobilityId": "11b232edb016b81d", "scanner": "scanner-primary", "fingerprint": "898e5e1bfb2fa7db", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48524"]}}, {"ruleId": "scanner-ceb7d3f88d95d998", "level": "warning", "message": {"text": "CVE-2025-71176: pytest 8.4.2 \u2014 uv.lock"}, "properties": {"repobilityId": "a7eb384608a8d52c", "scanner": "scanner-primary", "fingerprint": "ceb7d3f88d95d998", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-71176"]}}, {"ruleId": "scanner-45a3f658873f06a0", "level": "error", "message": {"text": "CVE-2026-42561: python-multipart 0.0.22 \u2014 uv.lock"}, "properties": {"repobilityId": "01c79a8395fad1cf", "scanner": "scanner-primary", "fingerprint": "45a3f658873f06a0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42561"]}}, {"ruleId": "scanner-2786a9b0b3069b17", "level": "error", "message": {"text": "CVE-2026-53539: python-multipart 0.0.22 \u2014 uv.lock"}, "properties": {"repobilityId": "25b2742cc7a21766", "scanner": "scanner-primary", "fingerprint": "2786a9b0b3069b17", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53539"]}}, {"ruleId": "scanner-97b2a0c8c6a3f837", "level": "warning", "message": {"text": "CVE-2026-40347: python-multipart 0.0.22 \u2014 uv.lock"}, "properties": {"repobilityId": "680bb151a8e1f602", "scanner": "scanner-primary", "fingerprint": "97b2a0c8c6a3f837", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40347"]}}, {"ruleId": "scanner-03498bee78ee13fc", "level": "note", "message": {"text": "CVE-2026-53537: python-multipart 0.0.22 \u2014 uv.lock"}, "properties": {"repobilityId": "f480cda055939429", "scanner": "scanner-primary", "fingerprint": "03498bee78ee13fc", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53537"]}}, {"ruleId": "scanner-30a81095cfb209fd", "level": "note", "message": {"text": "CVE-2026-53538: python-multipart 0.0.22 \u2014 uv.lock"}, "properties": {"repobilityId": "2458c0fb8d686551", "scanner": "scanner-primary", "fingerprint": "30a81095cfb209fd", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53538"]}}, {"ruleId": "scanner-ccf066f01b5cb8b5", "level": "note", "message": {"text": "CVE-2026-53540: python-multipart 0.0.22 \u2014 uv.lock"}, "properties": {"repobilityId": "68c69c7c120812e6", "scanner": "scanner-primary", "fingerprint": "ccf066f01b5cb8b5", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53540"]}}, {"ruleId": "scanner-f0bc6a832539e0bf", "level": "warning", "message": {"text": "CVE-2026-25645: requests 2.32.5 \u2014 uv.lock"}, "properties": {"repobilityId": "b5480ea7888fdcde", "scanner": "scanner-primary", "fingerprint": "f0bc6a832539e0bf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25645"]}}, {"ruleId": "scanner-48fdd935e384c638", "level": "warning", "message": {"text": "CVE-2026-59890: setuptools 82.0.1 \u2014 uv.lock"}, "properties": {"repobilityId": "e9190b412dfee1c0", "scanner": "scanner-primary", "fingerprint": "48fdd935e384c638", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59890"]}}, {"ruleId": "scanner-c1918baaeda2a82e", "level": "error", "message": {"text": "CVE-2026-48818: starlette 0.52.1 \u2014 uv.lock"}, "properties": {"repobilityId": "5fd9b65620eff6b1", "scanner": "scanner-primary", "fingerprint": "c1918baaeda2a82e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48818"]}}, {"ruleId": "scanner-fa7290bdf7d5e488", "level": "error", "message": {"text": "CVE-2026-54283: starlette 0.52.1 \u2014 uv.lock"}, "properties": {"repobilityId": "a28cb20663a761ec", "scanner": "scanner-primary", "fingerprint": "fa7290bdf7d5e488", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54283"]}}, {"ruleId": "scanner-faf17bae7b85853f", "level": "warning", "message": {"text": "CVE-2026-48710: starlette 0.52.1 \u2014 uv.lock"}, "properties": {"repobilityId": "e8ddf94c396d6dd1", "scanner": "scanner-primary", "fingerprint": "faf17bae7b85853f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48710"]}}, {"ruleId": "scanner-c7ce42faf6fe55e8", "level": "warning", "message": {"text": "CVE-2026-48817: starlette 0.52.1 \u2014 uv.lock"}, "properties": {"repobilityId": "315c33072892be6b", "scanner": "scanner-primary", "fingerprint": "c7ce42faf6fe55e8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48817"]}}, {"ruleId": "scanner-914c66c6e81b6efd", "level": "note", "message": {"text": "CVE-2026-54282: starlette 0.52.1 \u2014 uv.lock"}, "properties": {"repobilityId": "9b07991a62551363", "scanner": "scanner-primary", "fingerprint": "914c66c6e81b6efd", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54282"]}}, {"ruleId": "scanner-1004df6c60dddfab", "level": "note", "message": {"text": "CVE-2025-3000: torch 2.10.0 \u2014 uv.lock"}, "properties": {"repobilityId": "bffa8b22ac5138b3", "scanner": "scanner-primary", "fingerprint": "1004df6c60dddfab", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3000"]}}, {"ruleId": "scanner-f1fae0d80ab9394f", "level": "error", "message": {"text": "CVE-2026-4372: transformers 4.57.6 \u2014 uv.lock"}, "properties": {"repobilityId": "f36ca49f12aa5a15", "scanner": "scanner-primary", "fingerprint": "f1fae0d80ab9394f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4372"]}}, {"ruleId": "scanner-5e5e145d4910fd84", "level": "error", "message": {"text": "CVE-2026-5241: transformers 4.57.6 \u2014 uv.lock"}, "properties": {"repobilityId": "0847e515b0b8498a", "scanner": "scanner-primary", "fingerprint": "5e5e145d4910fd84", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-5241"]}}, {"ruleId": "scanner-e8302bac4a3063d2", "level": "warning", "message": {"text": "CVE-2026-1839: transformers 4.57.6 \u2014 uv.lock"}, "properties": {"repobilityId": "94f283730a698165", "scanner": "scanner-primary", "fingerprint": "e8302bac4a3063d2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-1839"]}}, {"ruleId": "scanner-9e9907f3d6ecddd1", "level": "error", "message": {"text": "CVE-2026-44431: urllib3 2.6.3 \u2014 uv.lock"}, "properties": {"repobilityId": "3621668d4ee670ac", "scanner": "scanner-primary", "fingerprint": "9e9907f3d6ecddd1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44431"]}}, {"ruleId": "scanner-4b91d7a02dcedfdc", "level": "error", "message": {"text": "CVE-2026-44432: urllib3 2.6.3 \u2014 uv.lock"}, "properties": {"repobilityId": "1ba97cfd649d1477", "scanner": "scanner-primary", "fingerprint": "4b91d7a02dcedfdc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44432"]}}, {"ruleId": "scanner-1d3afc046c6f851f", "level": "warning", "message": {"text": "AWS-0010: Cloudfront distribution should have Access Logging configured \u2014 tests/fixtures/sample.tf"}, "properties": {"repobilityId": "3cd8077719d8c750", "scanner": "scanner-primary", "fingerprint": "1d3afc046c6f851f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-b4278c98d18b57d8", "level": "error", "message": {"text": "AWS-0011: CloudFront distribution does not have a WAF in front. \u2014 tests/fixtures/sample.tf"}, "properties": {"repobilityId": "3ae852e52d2dff22", "scanner": "scanner-primary", "fingerprint": "b4278c98d18b57d8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-65a2298c439a7e49", "level": "error", "message": {"text": "AWS-0013: CloudFront distribution uses outdated SSL/TLS protocols. \u2014 tests/fixtures/sample.tf"}, "properties": {"repobilityId": "c053d4c091201856", "scanner": "scanner-primary", "fingerprint": "65a2298c439a7e49", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-aef6876203d7dbb3", "level": "error", "message": {"text": "AWS-0028: aws_instance should activate session tokens for Instance Metadata Service. \u2014 tests/fixtures/sample.tf"}, "properties": {"repobilityId": "efc957b4ae47e926", "scanner": "scanner-primary", "fingerprint": "aef6876203d7dbb3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-d403f777b4436c95", "level": "error", "message": {"text": "AWS-0086: S3 Access block should block public ACL \u2014 tests/fixtures/sample.tf"}, "properties": {"repobilityId": "724d11d94efdb3f0", "scanner": "scanner-primary", "fingerprint": "d403f777b4436c95", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-8ff34176b69ecdbc", "level": "error", "message": {"text": "AWS-0087: S3 Access block should block public policy \u2014 tests/fixtures/sample.tf"}, "properties": {"repobilityId": "396395e486cde4ef", "scanner": "scanner-primary", "fingerprint": "8ff34176b69ecdbc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-92c463c3e5a6a184", "level": "note", "message": {"text": "AWS-0089: S3 Bucket Logging \u2014 tests/fixtures/sample.tf"}, "properties": {"repobilityId": "7a5efafd9631ad4d", "scanner": "scanner-primary", "fingerprint": "92c463c3e5a6a184", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-ed6d274797e09e31", "level": "warning", "message": {"text": "AWS-0090: S3 Data should be versioned \u2014 tests/fixtures/sample.tf"}, "properties": {"repobilityId": "23f8afb6b8ce7ba3", "scanner": "scanner-primary", "fingerprint": "ed6d274797e09e31", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-aa7ffddac4beab51", "level": "error", "message": {"text": "AWS-0091: S3 Access Block should Ignore Public ACL \u2014 tests/fixtures/sample.tf"}, "properties": {"repobilityId": "fed8f9a03de1b1a7", "scanner": "scanner-primary", "fingerprint": "aa7ffddac4beab51", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-9c8cac6d9aa76956", "level": "error", "message": {"text": "AWS-0093: S3 Access block should restrict public bucket to limit access \u2014 tests/fixtures/sample.tf"}, "properties": {"repobilityId": "fbe3594ac4ba7854", "scanner": "scanner-primary", "fingerprint": "9c8cac6d9aa76956", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-e1dfa45741968f1b", "level": "note", "message": {"text": "AWS-0094: S3 buckets should each define an aws_s3_bucket_public_access_block \u2014 tests/fixtures/sample.tf"}, "properties": {"repobilityId": "414f1d9f09c60261", "scanner": "scanner-primary", "fingerprint": "e1dfa45741968f1b", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-ec849873b2ff7fde", "level": "note", "message": {"text": "AWS-0099: Missing description for security group. \u2014 tests/fixtures/sample.tf"}, "properties": {"repobilityId": "e7e29598c8791bf8", "scanner": "scanner-primary", "fingerprint": "ec849873b2ff7fde", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-74d732e4441a1ee8", "level": "error", "message": {"text": "AWS-0131: Instance with unencrypted block device. \u2014 tests/fixtures/sample.tf"}, "properties": {"repobilityId": "ba8641095c8a7c91", "scanner": "scanner-primary", "fingerprint": "74d732e4441a1ee8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-f8d8f2c7c0f0b274", "level": "error", "message": {"text": "AWS-0132: S3 encryption should use Customer Managed Keys \u2014 tests/fixtures/sample.tf"}, "properties": {"repobilityId": "ac04007951f5b476", "scanner": "scanner-primary", "fingerprint": "f8d8f2c7c0f0b274", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-c5ba387128707ed3", "level": "warning", "message": {"text": "AWS-0178: VPC Flow Logs is a feature that enables you to capture information about the IP traffic going to and from network interfaces in your VPC. After you've created a flow log, you can view and retrieve its data in Amazon CloudWatch Logs. It is recommended that VPC Flow Logs be enabled for packe"}, "properties": {"repobilityId": "0ef0dfe51ec06020", "scanner": "scanner-primary", "fingerprint": "c5ba387128707ed3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-cc55229a7a3c078d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .mcp.json"}, "properties": {"repobilityId": "51942fb3d5b8b5b4", "scanner": "scanner-primary", "fingerprint": "cc55229a7a3c078d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "mcp_config"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".mcp.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1374f6c12aca44ef", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: skills/build-graph/SKILL.md"}, "properties": {"repobilityId": "b6c7ce3bda8aa16a", "scanner": "scanner-primary", "fingerprint": "1374f6c12aca44ef", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "skill_file"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/build-graph/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5bb7f44128a743ce", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: skills/debug-issue/SKILL.md"}, "properties": {"repobilityId": "de478ff7f0ab1d11", "scanner": "scanner-primary", "fingerprint": "5bb7f44128a743ce", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "skill_file"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/debug-issue/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5d75407ba9df972d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: skills/explore-codebase/SKILL.md"}, "properties": {"repobilityId": "63634cbc1bf53e86", "scanner": "scanner-primary", "fingerprint": "5d75407ba9df972d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "skill_file"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/explore-codebase/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e725d2ab884fbd49", "level": "note", "message": {"text": "Multiple root agent instruction files without precedence"}, "properties": {"repobilityId": "1953db6c89508d22", "scanner": "scanner-primary", "fingerprint": "e725d2ab884fbd49", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["agent-instructions", "governance"]}}, {"ruleId": "scanner-e637c415447867e4", "level": "none", "message": {"text": "Run SkillSpector's LLM-backed analysis in your own pipeline"}, "properties": {"repobilityId": "1936f198ff5212bf", "scanner": "scanner-primary", "fingerprint": "e637c415447867e4", "layer": "security", "severity": "info", "confidence": 1.0, "tags": ["skillspector", "mcp-skill", "llm-advisory", "ai-coder"]}}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-22eb1ca4a4a0b655", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in code_review_graph/visualization.py:829"}, "properties": {"repobilityId": "12eddb9ea82498cf", "scanner": "scanner-primary", "fingerprint": "22eb1ca4a4a0b655", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/visualization.py"}, "region": {"startLine": 829}}}]}, {"ruleId": "scanner-e4290e1c65eed254", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in code-review-graph-vscode/src/webview/graph.ts:670"}, "properties": {"repobilityId": "898d14b9c2643857", "scanner": "scanner-primary", "fingerprint": "e4290e1c65eed254", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code-review-graph-vscode/src/webview/graph.ts"}, "region": {"startLine": 670}}}]}, {"ruleId": "scanner-41f42c7b617f44e1", "level": "error", "message": {"text": "Insecure pattern 'eval_used' in .github/workflows/eval.yml:56"}, "properties": {"repobilityId": "817ca206e3bf372b", "scanner": "scanner-primary", "fingerprint": "41f42c7b617f44e1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "eval_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/eval.yml"}, "region": {"startLine": 56}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-5d2dba911b3e3517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "de4cb28dd99688cb", "scanner": "scanner-primary", "fingerprint": "5d2dba911b3e3517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/eval.yml"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "1b0add4759a308ec", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-c3f98450e67bb718", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "160f4f58eda21e78", "scanner": "scanner-primary", "fingerprint": "c3f98450e67bb718", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/pr-review-comment.yml"}, "region": {"startLine": 56}}}]}, {"ruleId": "scanner-d5c51560effec079", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "eb428cdb07800d04", "scanner": "scanner-primary", "fingerprint": "d5c51560effec079", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/pr-review.yml"}, "region": {"startLine": 37}}}]}, {"ruleId": "scanner-a53bf972e19b52fd", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "e41d383711839b43", "scanner": "scanner-primary", "fingerprint": "a53bf972e19b52fd", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish.yml"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-7e53db065dcd3489", "level": "note", "message": {"text": "Very large file: tests/test_parser.py (1518 lines)"}, "properties": {"repobilityId": "cec36c0f3b438509", "scanner": "scanner-primary", "fingerprint": "7e53db065dcd3489", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-2fb7eb6adbfeab40", "level": "note", "message": {"text": "Very large file: tests/test_skills.py (2189 lines)"}, "properties": {"repobilityId": "9488ec01802da017", "scanner": "scanner-primary", "fingerprint": "2fb7eb6adbfeab40", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-0082b4ba3a556d3c", "level": "note", "message": {"text": "Very large file: tests/test_multilang.py (3669 lines)"}, "properties": {"repobilityId": "ec94f9166ec13e83", "scanner": "scanner-primary", "fingerprint": "0082b4ba3a556d3c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-8c91d22584884882", "level": "note", "message": {"text": "Very large file: tests/test_tools.py (2092 lines)"}, "properties": {"repobilityId": "0c773fe1bff8475b", "scanner": "scanner-primary", "fingerprint": "8c91d22584884882", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-29c71b3dab52081e", "level": "note", "message": {"text": "Very large file: code_review_graph/parser.py (14182 lines)"}, "properties": {"repobilityId": "df312037657bf777", "scanner": "scanner-primary", "fingerprint": "29c71b3dab52081e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-26272a619f08632a", "level": "note", "message": {"text": "Very large file: code_review_graph/skills.py (1713 lines)"}, "properties": {"repobilityId": "620d0db9732d979c", "scanner": "scanner-primary", "fingerprint": "26272a619f08632a", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-49acc8c09f06bdbc", "level": "note", "message": {"text": "Very large file: code_review_graph/graph.py (1633 lines)"}, "properties": {"repobilityId": "507b2847800e0375", "scanner": "scanner-primary", "fingerprint": "49acc8c09f06bdbc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-a0fe836eb94cbaa7", "level": "note", "message": {"text": "Very large file: code_review_graph/cli.py (1783 lines)"}, "properties": {"repobilityId": "f28cdd4c12b806cb", "scanner": "scanner-primary", "fingerprint": "a0fe836eb94cbaa7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ea11ed5d22a6d842", "level": "note", "message": {"text": "Very large file: code_review_graph/visualization.py (2234 lines)"}, "properties": {"repobilityId": "3cf14dc1d18c54c9", "scanner": "scanner-primary", "fingerprint": "ea11ed5d22a6d842", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "f7ca9620714cd098", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "9e25fda4589236ee", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "a7648f34e22486ae", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-d662004ab2a1a2c9", "level": "note", "message": {"text": "Stub function `add` (body is just `pass`/`return`) \u2014 code_review_graph/parser.py:5486"}, "properties": {"repobilityId": "3e6ee5158284e1ef", "scanner": "scanner-primary", "fingerprint": "d662004ab2a1a2c9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-095a2ab0b0b796fb", "level": "note", "message": {"text": "Legacy-named symbol `_migrate_v2` in code_review_graph/migrations.py:74"}, "properties": {"repobilityId": "b0387f7646b8cd36", "scanner": "scanner-primary", "fingerprint": "095a2ab0b0b796fb", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-2e1c04c39d7ea17d", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 code_review_graph/daemon.py:1058"}, "properties": {"repobilityId": "79b9b9b948d94449", "scanner": "scanner-primary", "fingerprint": "2e1c04c39d7ea17d", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/daemon.py"}, "region": {"startLine": 1058}}}]}, {"ruleId": "scanner-ec349c8142f6b07e", "level": "note", "message": {"text": "Stub function `embed` (body is just `pass`/`return`) \u2014 code_review_graph/embeddings.py:48"}, "properties": {"repobilityId": "03af919f88795cfb", "scanner": "scanner-primary", "fingerprint": "ec349c8142f6b07e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-20146c64919188a2", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 code_review_graph/eval/runner.py:97"}, "properties": {"repobilityId": "59d4d776fe2ce802", "scanner": "scanner-primary", "fingerprint": "20146c64919188a2", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/eval/runner.py"}, "region": {"startLine": 97}}}]}, {"ruleId": "scanner-0eacf55a92f0e83a", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 code_review_graph/eval/benchmarks/token_efficiency.py:28"}, "properties": {"repobilityId": "dc81d8023c23b225", "scanner": "scanner-primary", "fingerprint": "0eacf55a92f0e83a", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/eval/benchmarks/token_efficiency.py"}, "region": {"startLine": 28}}}]}, {"ruleId": "scanner-9de5f4a8380ccd03", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 code_review_graph/eval/benchmarks/impact_accuracy.py:35"}, "properties": {"repobilityId": "a54ac63b39b76d77", "scanner": "scanner-primary", "fingerprint": "9de5f4a8380ccd03", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code_review_graph/eval/benchmarks/impact_accuracy.py"}, "region": {"startLine": 35}}}]}, {"ruleId": "scanner-8df7778a2c07d890", "level": "warning", "message": {"text": "Vulnerable dependency esbuild 0.20.2: GHSA-67mh-4wv8-2f99"}, "properties": {"repobilityId": "3b45cb8f4f49ff5f", "scanner": "scanner-primary", "fingerprint": "8df7778a2c07d890", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-67mh-4wv8-2f99", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code-review-graph-vscode/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-31c55f92e38390ae", "level": "warning", "message": {"text": "Vulnerable dependency mcp 1.26.0: GHSA-hvrp-rf83-w775"}, "properties": {"repobilityId": "372a3eab7c0415af", "scanner": "scanner-primary", "fingerprint": "31c55f92e38390ae", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hvrp-rf83-w775"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-013c1a6cb91e1208", "level": "warning", "message": {"text": "Vulnerable dependency mcp 1.26.0: GHSA-jpw9-pfvf-9f58"}, "properties": {"repobilityId": "b1057d1f32458bbd", "scanner": "scanner-primary", "fingerprint": "013c1a6cb91e1208", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jpw9-pfvf-9f58"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-db23505d0ca43798", "level": "warning", "message": {"text": "Vulnerable dependency mcp 1.26.0: GHSA-vj7q-gjh5-988w"}, "properties": {"repobilityId": "131e03c60523a66a", "scanner": "scanner-primary", "fingerprint": "db23505d0ca43798", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vj7q-gjh5-988w"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7de3f4e26f938151", "level": "warning", "message": {"text": "Vulnerable dependency mcp 1.26.0: PYSEC-2026-3481"}, "properties": {"repobilityId": "64420dfe890022e2", "scanner": "scanner-primary", "fingerprint": "7de3f4e26f938151", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3481"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c37a69a109c975c8", "level": "warning", "message": {"text": "Vulnerable dependency mcp 1.26.0: PYSEC-2026-3482"}, "properties": {"repobilityId": "5d0c0e703af632a8", "scanner": "scanner-primary", "fingerprint": "c37a69a109c975c8", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3482"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2f770ca3a3d8759f", "level": "warning", "message": {"text": "Vulnerable dependency mcp 1.26.0: PYSEC-2026-3483"}, "properties": {"repobilityId": "7987c6d2f17744d9", "scanner": "scanner-primary", "fingerprint": "2f770ca3a3d8759f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3483"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8bf960b79a4f13f6", "level": "warning", "message": {"text": "Vulnerable dependency pytest 8.4.2: GHSA-6w46-j5rx-g56g"}, "properties": {"repobilityId": "de8961e2e4d06cd6", "scanner": "scanner-primary", "fingerprint": "8bf960b79a4f13f6", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-6w46-j5rx-g56g", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4e4a8e70187fa015", "level": "warning", "message": {"text": "Vulnerable dependency pytest 8.4.2: PYSEC-2026-1845"}, "properties": {"repobilityId": "16c73a172a19f24c", "scanner": "scanner-primary", "fingerprint": "4e4a8e70187fa015", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-1845", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-10168b55251b60df", "level": "error", "message": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-3jxr-9vmj-r5cp"}, "properties": {"repobilityId": "5d2ce580505ef5a7", "scanner": "scanner-primary", "fingerprint": "10168b55251b60df", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3jxr-9vmj-r5cp", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code-review-graph-vscode/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b8deafc87a401a66", "level": "warning", "message": {"text": "Vulnerable dependency brace-expansion 1.1.12: GHSA-f886-m6hf-6m8v"}, "properties": {"repobilityId": "c4fa6cea7167ee7e", "scanner": "scanner-primary", "fingerprint": "b8deafc87a401a66", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-f886-m6hf-6m8v", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code-review-graph-vscode/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ef61ade861eb31d7", "level": "warning", "message": {"text": "Vulnerable dependency form-data 4.0.5: GHSA-hmw2-7cc7-3qxx"}, "properties": {"repobilityId": "ad1cdc8bb6564feb", "scanner": "scanner-primary", "fingerprint": "ef61ade861eb31d7", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-hmw2-7cc7-3qxx", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code-review-graph-vscode/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-47578c9cb1ee419d", "level": "error", "message": {"text": "Vulnerable dependency linkify-it 3.0.3: GHSA-22p9-wv53-3rq4"}, "properties": {"repobilityId": "ac7f63cf106a4876", "scanner": "scanner-primary", "fingerprint": "47578c9cb1ee419d", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-22p9-wv53-3rq4", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code-review-graph-vscode/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-137c0886e1efbf85", "level": "warning", "message": {"text": "Vulnerable dependency linkify-it 3.0.3: GHSA-v245-v573-v5vm"}, "properties": {"repobilityId": "93b7ab82f9328ee6", "scanner": "scanner-primary", "fingerprint": "137c0886e1efbf85", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-v245-v573-v5vm", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code-review-graph-vscode/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dece238f02200800", "level": "warning", "message": {"text": "Vulnerable dependency markdown-it 12.3.2: GHSA-6v5v-wf23-fmfq"}, "properties": {"repobilityId": "3691604722b9b6f8", "scanner": "scanner-primary", "fingerprint": "dece238f02200800", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-6v5v-wf23-fmfq", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code-review-graph-vscode/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-582d6a8fd069c942", "level": "warning", "message": {"text": "Vulnerable dependency qs 6.15.0: GHSA-q8mj-m7cp-5q26"}, "properties": {"repobilityId": "cf00f2c788125541", "scanner": "scanner-primary", "fingerprint": "582d6a8fd069c942", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-q8mj-m7cp-5q26", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code-review-graph-vscode/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5e90641b6eb585c2", "level": "warning", "message": {"text": "Vulnerable dependency tmp 0.2.5: GHSA-ph9p-34f9-6g65"}, "properties": {"repobilityId": "32fbe112457d6ee9", "scanner": "scanner-primary", "fingerprint": "5e90641b6eb585c2", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-ph9p-34f9-6g65", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code-review-graph-vscode/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a9515e0af2bd3637", "level": "note", "message": {"text": "Vulnerable dependency undici 7.24.4: GHSA-35p6-xmwp-9g52"}, "properties": {"repobilityId": "b4bd173a5261e7c4", "scanner": "scanner-primary", "fingerprint": "a9515e0af2bd3637", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-35p6-xmwp-9g52", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code-review-graph-vscode/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a8a5a095709d1612", "level": "note", "message": {"text": "Vulnerable dependency undici 7.24.4: GHSA-g8m3-5g58-fq7m"}, "properties": {"repobilityId": "bd305bc32321cb5a", "scanner": "scanner-primary", "fingerprint": "a8a5a095709d1612", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-g8m3-5g58-fq7m", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code-review-graph-vscode/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3d68c82312856e2f", "level": "warning", "message": {"text": "Vulnerable dependency undici 7.24.4: GHSA-hm92-r4w5-c3mj"}, "properties": {"repobilityId": "0070f7e15ab71179", "scanner": "scanner-primary", "fingerprint": "3d68c82312856e2f", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-hm92-r4w5-c3mj", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code-review-graph-vscode/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9a23c65275c433b4", "level": "warning", "message": {"text": "Vulnerable dependency undici 7.24.4: GHSA-p88m-4jfj-68fv"}, "properties": {"repobilityId": "c14dd4fa735a09fd", "scanner": "scanner-primary", "fingerprint": "9a23c65275c433b4", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-p88m-4jfj-68fv", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code-review-graph-vscode/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-618e4472e678bf64", "level": "warning", "message": {"text": "Vulnerable dependency undici 7.24.4: GHSA-pr7r-676h-xcf6"}, "properties": {"repobilityId": "c59da3fec2529e25", "scanner": "scanner-primary", "fingerprint": "618e4472e678bf64", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-pr7r-676h-xcf6", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code-review-graph-vscode/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4086cda2616be531", "level": "error", "message": {"text": "Vulnerable dependency undici 7.24.4: GHSA-vmh5-mc38-953g"}, "properties": {"repobilityId": "c89ba1cf769c07ef", "scanner": "scanner-primary", "fingerprint": "4086cda2616be531", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-vmh5-mc38-953g", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code-review-graph-vscode/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3a359e3a8eeda44f", "level": "error", "message": {"text": "Vulnerable dependency undici 7.24.4: GHSA-vxpw-j846-p89q"}, "properties": {"repobilityId": "9fd61c7106fe867e", "scanner": "scanner-primary", "fingerprint": "3a359e3a8eeda44f", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-vxpw-j846-p89q", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code-review-graph-vscode/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-104b90bc80ecf1b8", "level": "warning", "message": {"text": "Vulnerable dependency uuid 8.3.2: GHSA-w5hq-g745-h8pq"}, "properties": {"repobilityId": "90ae1f5d3eb9ff69", "scanner": "scanner-primary", "fingerprint": "104b90bc80ecf1b8", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-w5hq-g745-h8pq", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code-review-graph-vscode/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-228596b9db26a39a", "level": "warning", "message": {"text": "Vulnerable dependency authlib 1.6.9: GHSA-jj8c-mmj3-mmgv"}, "properties": {"repobilityId": "546e97dbd6aa28a5", "scanner": "scanner-primary", "fingerprint": "228596b9db26a39a", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-jj8c-mmj3-mmgv", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e04c51e47cd6f34e", "level": "warning", "message": {"text": "Vulnerable dependency authlib 1.6.9: GHSA-r95x-qfjj-fjj2"}, "properties": {"repobilityId": "f36b5fe18214b0c2", "scanner": "scanner-primary", "fingerprint": "e04c51e47cd6f34e", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-r95x-qfjj-fjj2", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2460e67d9ae67a48", "level": "warning", "message": {"text": "Vulnerable dependency authlib 1.6.9: GHSA-w8p2-r796-3vmq"}, "properties": {"repobilityId": "4ff9fa2bd3157dfb", "scanner": "scanner-primary", "fingerprint": "2460e67d9ae67a48", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-w8p2-r796-3vmq", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a8f25b38c7e5c630", "level": "warning", "message": {"text": "Vulnerable dependency authlib 1.6.9: PYSEC-2026-188"}, "properties": {"repobilityId": "2cc96b91379f1968", "scanner": "scanner-primary", "fingerprint": "a8f25b38c7e5c630", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-188", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8008a828705b7d9b", "level": "warning", "message": {"text": "Vulnerable dependency authlib 1.6.9: PYSEC-2026-2119"}, "properties": {"repobilityId": "0aebd2d753f10478", "scanner": "scanner-primary", "fingerprint": "8008a828705b7d9b", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2119", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9e7fcd6291dd8889", "level": "warning", "message": {"text": "Vulnerable dependency authlib 1.6.9: PYSEC-2026-25"}, "properties": {"repobilityId": "b77210b09ddaeb50", "scanner": "scanner-primary", "fingerprint": "9e7fcd6291dd8889", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-25", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5ad35f96d45e1160", "level": "warning", "message": {"text": "Vulnerable dependency click 8.3.1: PYSEC-2026-2132"}, "properties": {"repobilityId": "346057e715e4d8e2", "scanner": "scanner-primary", "fingerprint": "5ad35f96d45e1160", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2132", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-56f30e4e335cd941", "level": "error", "message": {"text": "Vulnerable dependency cryptography 46.0.5: GHSA-537c-gmf6-5ccf"}, "properties": {"repobilityId": "a9fda834958707e5", "scanner": "scanner-primary", "fingerprint": "56f30e4e335cd941", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-537c-gmf6-5ccf", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2c1fe042cd666315", "level": "warning", "message": {"text": "Vulnerable dependency cryptography 46.0.5: GHSA-m959-cc7f-wv43"}, "properties": {"repobilityId": "4f3921468c8a7081", "scanner": "scanner-primary", "fingerprint": "2c1fe042cd666315", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-m959-cc7f-wv43", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ed5ae94bd58f2494", "level": "warning", "message": {"text": "Vulnerable dependency cryptography 46.0.5: GHSA-p423-j2cm-9vmq"}, "properties": {"repobilityId": "aeea12638156168c", "scanner": "scanner-primary", "fingerprint": "ed5ae94bd58f2494", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-p423-j2cm-9vmq", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-50bc92ac457cfd47", "level": "warning", "message": {"text": "Vulnerable dependency cryptography 46.0.5: PYSEC-2026-35"}, "properties": {"repobilityId": "5fc422dfe1001d48", "scanner": "scanner-primary", "fingerprint": "50bc92ac457cfd47", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-35", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-75b8a847d15ce6af", "level": "warning", "message": {"text": "Vulnerable dependency cryptography 46.0.5: PYSEC-2026-36"}, "properties": {"repobilityId": "49e38ea699ba8b38", "scanner": "scanner-primary", "fingerprint": "75b8a847d15ce6af", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-36", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fe17a667e654d9a8", "level": "warning", "message": {"text": "Vulnerable dependency httplib2 0.31.2: PYSEC-2026-3444"}, "properties": {"repobilityId": "aed71e6dba5781c3", "scanner": "scanner-primary", "fingerprint": "fe17a667e654d9a8", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3444", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9eb78ac091ef83de", "level": "warning", "message": {"text": "Vulnerable dependency idna 3.11: GHSA-65pc-fj4g-8rjx"}, "properties": {"repobilityId": "fb9a242b2a48123b", "scanner": "scanner-primary", "fingerprint": "9eb78ac091ef83de", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-65pc-fj4g-8rjx", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4c4819f412cee4dc", "level": "error", "message": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-45hq-cxwh-f6vc"}, "properties": {"repobilityId": "0ec60ccc64839061", "scanner": "scanner-primary", "fingerprint": "4c4819f412cee4dc", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-45hq-cxwh-f6vc", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5f8921bf03f2406a", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-4x4j-2g7c-83w6"}, "properties": {"repobilityId": "49c879d6906e6584", "scanner": "scanner-primary", "fingerprint": "5f8921bf03f2406a", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-4x4j-2g7c-83w6", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c7d443194adfb20e", "level": "error", "message": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-5x94-69rx-g8h2"}, "properties": {"repobilityId": "e4de602c6f28bf4a", "scanner": "scanner-primary", "fingerprint": "c7d443194adfb20e", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-5x94-69rx-g8h2", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5f5f03af8b9e5f97", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-5xmw-vc9v-4wf2"}, "properties": {"repobilityId": "893ec4d14816693b", "scanner": "scanner-primary", "fingerprint": "5f5f03af8b9e5f97", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-5xmw-vc9v-4wf2", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c90c2cc3242986d1", "level": "error", "message": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-62p4-gmf7-7g93"}, "properties": {"repobilityId": "a9fffb43519f6045", "scanner": "scanner-primary", "fingerprint": "c90c2cc3242986d1", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-62p4-gmf7-7g93", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b67d5225f870cc79", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-6r8x-57c9-28j4"}, "properties": {"repobilityId": "9a81138216fbc969", "scanner": "scanner-primary", "fingerprint": "b67d5225f870cc79", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-6r8x-57c9-28j4", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a6ffb483913324f2", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-8v84-f9pq-wr9x"}, "properties": {"repobilityId": "1e38354a5b6bbf85", "scanner": "scanner-primary", "fingerprint": "a6ffb483913324f2", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-8v84-f9pq-wr9x", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ba9b4810598e0a86", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-9hw9-ch79-4vh6"}, "properties": {"repobilityId": "e2bcc70bfdb1bd80", "scanner": "scanner-primary", "fingerprint": "ba9b4810598e0a86", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-9hw9-ch79-4vh6", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5bd959f531adfcdb", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-fj7v-r99m-22gq"}, "properties": {"repobilityId": "368759d08d7633c7", "scanner": "scanner-primary", "fingerprint": "5bd959f531adfcdb", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-fj7v-r99m-22gq", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-04e0686c4f897099", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-jjj6-mw9f-p565"}, "properties": {"repobilityId": "0f142dd78e4e1acc", "scanner": "scanner-primary", "fingerprint": "04e0686c4f897099", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-jjj6-mw9f-p565", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0b61d497510c1f45", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-pg7v-jwj7-p798"}, "properties": {"repobilityId": "c76f79472b669489", "scanner": "scanner-primary", "fingerprint": "0b61d497510c1f45", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-pg7v-jwj7-p798", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d97c0d4e3887ff59", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-phj9-mv4w-65pm"}, "properties": {"repobilityId": "d2531c54afa2ddd0", "scanner": "scanner-primary", "fingerprint": "d97c0d4e3887ff59", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-phj9-mv4w-65pm", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fbe64b3bb98a7411", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-pwv6-vv43-88gr"}, "properties": {"repobilityId": "bd437661d5c46ba3", "scanner": "scanner-primary", "fingerprint": "fbe64b3bb98a7411", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-pwv6-vv43-88gr", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-902035c4ddd9193c", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-r73j-pqj5-w3x7"}, "properties": {"repobilityId": "1522fb70a8f370ae", "scanner": "scanner-primary", "fingerprint": "902035c4ddd9193c", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-r73j-pqj5-w3x7", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7bd98520a60583dc", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-vjc4-5qp5-m44j"}, "properties": {"repobilityId": "f2e99059ab317256", "scanner": "scanner-primary", "fingerprint": "7bd98520a60583dc", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-vjc4-5qp5-m44j", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-74d39e9c88f2e784", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-whj4-6x5x-4v2j"}, "properties": {"repobilityId": "cd48021f0032cccf", "scanner": "scanner-primary", "fingerprint": "74d39e9c88f2e784", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-whj4-6x5x-4v2j", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-681299b493aad42a", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-wjx4-4jcj-g98j"}, "properties": {"repobilityId": "912ddd3496ea594b", "scanner": "scanner-primary", "fingerprint": "681299b493aad42a", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-wjx4-4jcj-g98j", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cbf499d877ebd15c", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: GHSA-xj96-63gp-2gmr"}, "properties": {"repobilityId": "8f722c76c9946800", "scanner": "scanner-primary", "fingerprint": "cbf499d877ebd15c", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-xj96-63gp-2gmr", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1ddcae6a88f7d119", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-165"}, "properties": {"repobilityId": "60a1cf5c1d48b710", "scanner": "scanner-primary", "fingerprint": "1ddcae6a88f7d119", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-165", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-65ae94d114639ce8", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-2250"}, "properties": {"repobilityId": "c6806e4fa8bde410", "scanner": "scanner-primary", "fingerprint": "65ae94d114639ce8", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2250", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e8e862ba3e0a1d52", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-2252"}, "properties": {"repobilityId": "a0fdde630d8cae19", "scanner": "scanner-primary", "fingerprint": "e8e862ba3e0a1d52", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2252", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c0c2cd13aecc738c", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-2253"}, "properties": {"repobilityId": "b0073a9e96d6cbfc", "scanner": "scanner-primary", "fingerprint": "c0c2cd13aecc738c", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2253", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b8f5700978cfff89", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-2256"}, "properties": {"repobilityId": "6c0774ccb977156f", "scanner": "scanner-primary", "fingerprint": "b8f5700978cfff89", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2256", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5d211138736351aa", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-2874"}, "properties": {"repobilityId": "b4917fe709e8a72e", "scanner": "scanner-primary", "fingerprint": "5d211138736351aa", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2874", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3bc3463012588ba5", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-3451"}, "properties": {"repobilityId": "27ba3465e36df180", "scanner": "scanner-primary", "fingerprint": "3bc3463012588ba5", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3451", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6fc9590ab689fec4", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-3452"}, "properties": {"repobilityId": "676d6c585821cf50", "scanner": "scanner-primary", "fingerprint": "6fc9590ab689fec4", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3452", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-05087a76da4ec480", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-3453"}, "properties": {"repobilityId": "b7e69803b74985e1", "scanner": "scanner-primary", "fingerprint": "05087a76da4ec480", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3453", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-52514d835e9bfe9a", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-3454"}, "properties": {"repobilityId": "31f1d2014ae30a7c", "scanner": "scanner-primary", "fingerprint": "52514d835e9bfe9a", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3454", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-563d1e13c71edb93", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-3494"}, "properties": {"repobilityId": "38a3d0cd1ef7e1a6", "scanner": "scanner-primary", "fingerprint": "563d1e13c71edb93", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3494", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4230330896223de4", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-3495"}, "properties": {"repobilityId": "d25afc25108a6fce", "scanner": "scanner-primary", "fingerprint": "4230330896223de4", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3495", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ac34956e395b775a", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.1.1: PYSEC-2026-3496"}, "properties": {"repobilityId": "d85083d44f8cb1fe", "scanner": "scanner-primary", "fingerprint": "ac34956e395b775a", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3496", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4be8be837d3218a8", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.3: GHSA-8ppf-4f7h-5ppj"}, "properties": {"repobilityId": "35f07a3a79393e33", "scanner": "scanner-primary", "fingerprint": "4be8be837d3218a8", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-8ppf-4f7h-5ppj", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2a40b871965f1506", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.3: GHSA-hm4w-wwcw-mr6r"}, "properties": {"repobilityId": "dadec8e86f1cd2fe", "scanner": "scanner-primary", "fingerprint": "2a40b871965f1506", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-hm4w-wwcw-mr6r", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f8b7f5ba4fa43ada", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.3: PYSEC-2026-3455"}, "properties": {"repobilityId": "2d11f7392b5f7352", "scanner": "scanner-primary", "fingerprint": "f8b7f5ba4fa43ada", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3455", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8c025f6c1aee6ca0", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.3: PYSEC-2026-3456"}, "properties": {"repobilityId": "c3522bbb62e44c0f", "scanner": "scanner-primary", "fingerprint": "8c025f6c1aee6ca0", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3456", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9bbf32ae7157c304", "level": "warning", "message": {"text": "Vulnerable dependency pyasn1 0.6.3: PYSEC-2026-3457"}, "properties": {"repobilityId": "b83fefaaea70e314", "scanner": "scanner-primary", "fingerprint": "9bbf32ae7157c304", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3457", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-561199607badef54", "level": "warning", "message": {"text": "Vulnerable dependency pydantic-settings 2.13.1: GHSA-4xgf-cpjx-pc3j"}, "properties": {"repobilityId": "c06b11fbfae6fa12", "scanner": "scanner-primary", "fingerprint": "561199607badef54", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-4xgf-cpjx-pc3j", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2f35e24090839556", "level": "warning", "message": {"text": "Vulnerable dependency pygments 2.19.2: GHSA-5239-wwwm-4pmq"}, "properties": {"repobilityId": "b5634ffa34a95a85", "scanner": "scanner-primary", "fingerprint": "2f35e24090839556", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-5239-wwwm-4pmq", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-15675fc0e6e4a478", "level": "warning", "message": {"text": "Vulnerable dependency pyjwt 2.12.1: GHSA-993g-76c3-p5m4"}, "properties": {"repobilityId": "11c1472c61646a5e", "scanner": "scanner-primary", "fingerprint": "15675fc0e6e4a478", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-993g-76c3-p5m4", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7c74016272c94101", "level": "warning", "message": {"text": "Vulnerable dependency pyjwt 2.12.1: GHSA-fhv5-28vv-h8m8"}, "properties": {"repobilityId": "3950dcdb41ba2ea8", "scanner": "scanner-primary", "fingerprint": "7c74016272c94101", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-fhv5-28vv-h8m8", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f4ff2ffc50e5625e", "level": "warning", "message": {"text": "Vulnerable dependency pyjwt 2.12.1: GHSA-jq35-7prp-9v3f"}, "properties": {"repobilityId": "1553b7e74ae03083", "scanner": "scanner-primary", "fingerprint": "f4ff2ffc50e5625e", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-jq35-7prp-9v3f", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7220572de8863f14", "level": "warning", "message": {"text": "Vulnerable dependency pyjwt 2.12.1: GHSA-w7vc-732c-9m39"}, "properties": {"repobilityId": "d6da3bb8d3d0eb86", "scanner": "scanner-primary", "fingerprint": "7220572de8863f14", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-w7vc-732c-9m39", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a663ffba8e01f884", "level": "warning", "message": {"text": "Vulnerable dependency pyjwt 2.12.1: GHSA-xgmm-8j9v-c9wx"}, "properties": {"repobilityId": "db7ea4051e62e8d9", "scanner": "scanner-primary", "fingerprint": "a663ffba8e01f884", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-xgmm-8j9v-c9wx", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7d880cf256dd06b6", "level": "warning", "message": {"text": "Vulnerable dependency pyjwt 2.12.1: PYSEC-2026-175"}, "properties": {"repobilityId": "8e667cb2d5cc3143", "scanner": "scanner-primary", "fingerprint": "7d880cf256dd06b6", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-175", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-306b94bda0170a97", "level": "warning", "message": {"text": "Vulnerable dependency pyjwt 2.12.1: PYSEC-2026-177"}, "properties": {"repobilityId": "289c70dbc07f842f", "scanner": "scanner-primary", "fingerprint": "306b94bda0170a97", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-177", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-954ab89c5884c7e6", "level": "warning", "message": {"text": "Vulnerable dependency pyjwt 2.12.1: PYSEC-2026-178"}, "properties": {"repobilityId": "81e6ad19153192c8", "scanner": "scanner-primary", "fingerprint": "954ab89c5884c7e6", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-178", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ef485dff6a0b4b22", "level": "warning", "message": {"text": "Vulnerable dependency pyjwt 2.12.1: PYSEC-2026-179"}, "properties": {"repobilityId": "8e2acf97936fabf5", "scanner": "scanner-primary", "fingerprint": "ef485dff6a0b4b22", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-179", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f4b15ef3314d46dd", "level": "error", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-5rvq-cxj2-64vf"}, "properties": {"repobilityId": "4f41851ea516bb0f", "scanner": "scanner-primary", "fingerprint": "f4b15ef3314d46dd", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-5rvq-cxj2-64vf", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a234e701f1591250", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-6jv3-5f52-599m"}, "properties": {"repobilityId": "66d5af8983f693af", "scanner": "scanner-primary", "fingerprint": "a234e701f1591250", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-6jv3-5f52-599m", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f071086931bc6bf3", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-mj87-hwqh-73pj"}, "properties": {"repobilityId": "7bff27eec4731ee3", "scanner": "scanner-primary", "fingerprint": "f071086931bc6bf3", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-mj87-hwqh-73pj", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-14d1ea28365214f4", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-pp6c-gr5w-3c5g"}, "properties": {"repobilityId": "014b999f1f965261", "scanner": "scanner-primary", "fingerprint": "14d1ea28365214f4", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-pp6c-gr5w-3c5g", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-50238634a6e27df0", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-v9pg-7xvm-68hf"}, "properties": {"repobilityId": "663738fec3cd7bf3", "scanner": "scanner-primary", "fingerprint": "50238634a6e27df0", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-v9pg-7xvm-68hf", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ce264103618eff28", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: GHSA-vffw-93wf-4j4q"}, "properties": {"repobilityId": "6f7b3b5ac1ccc65f", "scanner": "scanner-primary", "fingerprint": "ce264103618eff28", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-vffw-93wf-4j4q", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-675e8fad05133489", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3037"}, "properties": {"repobilityId": "3397e4bdf58b4620", "scanner": "scanner-primary", "fingerprint": "675e8fad05133489", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3037", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5a8001ff392d339c", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3038"}, "properties": {"repobilityId": "7f85ddb03b451085", "scanner": "scanner-primary", "fingerprint": "5a8001ff392d339c", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3038", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-87057aa9b7c3dfe7", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3039"}, "properties": {"repobilityId": "0542a2b6b9d7f33f", "scanner": "scanner-primary", "fingerprint": "87057aa9b7c3dfe7", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3039", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-727fff841f1fca00", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3040"}, "properties": {"repobilityId": "d1aad14e8e40c34a", "scanner": "scanner-primary", "fingerprint": "727fff841f1fca00", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3040", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-df64a46023050a34", "level": "warning", "message": {"text": "Vulnerable dependency python-multipart 0.0.22: PYSEC-2026-3041"}, "properties": {"repobilityId": "e662c64103e6ef60", "scanner": "scanner-primary", "fingerprint": "df64a46023050a34", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3041", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8da0231e5842f2d7", "level": "warning", "message": {"text": "Vulnerable dependency requests 2.32.5: GHSA-gc5v-m9x4-r6x2"}, "properties": {"repobilityId": "5a83342b2ace364f", "scanner": "scanner-primary", "fingerprint": "8da0231e5842f2d7", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-gc5v-m9x4-r6x2", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fb139b5396a6b198", "level": "warning", "message": {"text": "Vulnerable dependency requests 2.32.5: PYSEC-2026-2275"}, "properties": {"repobilityId": "9ca627556ae0371e", "scanner": "scanner-primary", "fingerprint": "fb139b5396a6b198", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2275", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-02beaef6201fc578", "level": "warning", "message": {"text": "Vulnerable dependency setuptools 82.0.1: GHSA-h35f-9h28-mq5c"}, "properties": {"repobilityId": "36330ba4f14508b6", "scanner": "scanner-primary", "fingerprint": "02beaef6201fc578", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-h35f-9h28-mq5c", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-128492a85849709f", "level": "warning", "message": {"text": "Vulnerable dependency setuptools 82.0.1: PYSEC-2026-3447"}, "properties": {"repobilityId": "c4aa24902be99332", "scanner": "scanner-primary", "fingerprint": "128492a85849709f", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3447", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f2c8013eb5eaff91", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.52.1: GHSA-82w8-qh3p-5jfq"}, "properties": {"repobilityId": "b251d93440cbabf3", "scanner": "scanner-primary", "fingerprint": "f2c8013eb5eaff91", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-82w8-qh3p-5jfq", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5c15b30fde69ed75", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.52.1: GHSA-86qp-5c8j-p5mr"}, "properties": {"repobilityId": "bfe8ab9063c6084a", "scanner": "scanner-primary", "fingerprint": "5c15b30fde69ed75", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-86qp-5c8j-p5mr", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-68d456f086a60172", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.52.1: GHSA-jp82-jpqv-5vv3"}, "properties": {"repobilityId": "67a5509c81c86f46", "scanner": "scanner-primary", "fingerprint": "68d456f086a60172", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-jp82-jpqv-5vv3", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fc8f5ac9a4f33f8f", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.52.1: GHSA-wqp7-x3pw-xc5r"}, "properties": {"repobilityId": "07cd6a5b2e071130", "scanner": "scanner-primary", "fingerprint": "fc8f5ac9a4f33f8f", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-wqp7-x3pw-xc5r", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7da100bb44b705f7", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.52.1: GHSA-x746-7m8f-x49c"}, "properties": {"repobilityId": "b734eb1689015a3c", "scanner": "scanner-primary", "fingerprint": "7da100bb44b705f7", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-x746-7m8f-x49c", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d045151a0b52dfbd", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-161"}, "properties": {"repobilityId": "a07c0c07cc0cf598", "scanner": "scanner-primary", "fingerprint": "d045151a0b52dfbd", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-161", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-db597718539d655b", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-2280"}, "properties": {"repobilityId": "1942c6f60e92bc32", "scanner": "scanner-primary", "fingerprint": "db597718539d655b", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2280", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-526a1dd33e27d6f5", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-2281"}, "properties": {"repobilityId": "6e311b680f1aaba6", "scanner": "scanner-primary", "fingerprint": "526a1dd33e27d6f5", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2281", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-28608c156a1a234a", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-248"}, "properties": {"repobilityId": "c4e67d11d07156d9", "scanner": "scanner-primary", "fingerprint": "28608c156a1a234a", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-248", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8ce24ff16c98d6d5", "level": "warning", "message": {"text": "Vulnerable dependency starlette 0.52.1: PYSEC-2026-249"}, "properties": {"repobilityId": "a36296b0e1a0a7f9", "scanner": "scanner-primary", "fingerprint": "8ce24ff16c98d6d5", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-249", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-598c14bfc13989e2", "level": "warning", "message": {"text": "Vulnerable dependency torch 2.10.0: GHSA-rrmf-rvhw-rf47"}, "properties": {"repobilityId": "1b41ff09403ad19f", "scanner": "scanner-primary", "fingerprint": "598c14bfc13989e2", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-rrmf-rvhw-rf47", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cd035c134e2bfaa7", "level": "warning", "message": {"text": "Vulnerable dependency torch 2.10.0: PYSEC-2026-139"}, "properties": {"repobilityId": "e55966d65ee3fc97", "scanner": "scanner-primary", "fingerprint": "cd035c134e2bfaa7", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-139", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f11679ab31b87155", "level": "error", "message": {"text": "Vulnerable dependency transformers 4.57.6: GHSA-29pf-2h5f-8g72"}, "properties": {"repobilityId": "fe6047dd3abb867e", "scanner": "scanner-primary", "fingerprint": "f11679ab31b87155", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-29pf-2h5f-8g72", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ca4664d7ef14cfd9", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.57.6: GHSA-69w3-r845-3855"}, "properties": {"repobilityId": "de46693b07b25ee6", "scanner": "scanner-primary", "fingerprint": "ca4664d7ef14cfd9", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-69w3-r845-3855", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ceebb417c6ccd532", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.57.6: GHSA-fgcw-684q-jj6r"}, "properties": {"repobilityId": "2693e05b51acfc82", "scanner": "scanner-primary", "fingerprint": "ceebb417c6ccd532", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-fgcw-684q-jj6r", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0cab1e5833db8f05", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.57.6: PYSEC-2025-217"}, "properties": {"repobilityId": "c2a886d3d2f115d2", "scanner": "scanner-primary", "fingerprint": "0cab1e5833db8f05", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2025-217", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-11d3f0e737cf8fe9", "level": "warning", "message": {"text": "Vulnerable dependency transformers 4.57.6: PYSEC-2026-2290"}, "properties": {"repobilityId": "b84f582545b72058", "scanner": "scanner-primary", "fingerprint": "11d3f0e737cf8fe9", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2290", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-47cc8878f0379db8", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.6.3: GHSA-mf9v-mfxr-j63j"}, "properties": {"repobilityId": "58bf68e0b735c3e5", "scanner": "scanner-primary", "fingerprint": "47cc8878f0379db8", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-mf9v-mfxr-j63j", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-433f57b90f387132", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.6.3: GHSA-qccp-gfcp-xxvc"}, "properties": {"repobilityId": "85d3ff0504c74b92", "scanner": "scanner-primary", "fingerprint": "433f57b90f387132", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-qccp-gfcp-xxvc", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9a7d4ee40fdfda62", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.6.3: PYSEC-2026-141"}, "properties": {"repobilityId": "701c2015b9d154c2", "scanner": "scanner-primary", "fingerprint": "9a7d4ee40fdfda62", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-141", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b0cc2808acdb73ab", "level": "warning", "message": {"text": "Vulnerable dependency urllib3 2.6.3: PYSEC-2026-142"}, "properties": {"repobilityId": "49390d2c616581f1", "scanner": "scanner-primary", "fingerprint": "b0cc2808acdb73ab", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "PYSEC-2026-142", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-718339b057a5c1f3", "level": "note", "message": {"text": "Dependency better-sqlite3 is a major version behind"}, "properties": {"repobilityId": "0c0afe6d89eb379d", "scanner": "scanner-primary", "fingerprint": "718339b057a5c1f3", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "code-review-graph-vscode/package.json"}, "region": {"startLine": 1}}}]}]}]}