Skip to content

security: 3 high-severity Dependabot alerts on default branch, gh api read returns empty #1397

Description

@kyle-sexton

Context

While pushing a work-loop branch (fix/324-review-trigger-gate-contract), git push reported:

"GitHub found 3 vulnerabilities on melodic-software/claude-code-plugins's default branch (3 high). To find out more, visit: https://github.com/melodic-software/claude-code-plugins/security/dependabot"

Attempted to check gh api repos/melodic-software/claude-code-plugins/dependabot/alerts from this session and got an empty result -- either the bound token lacks the security_events/Dependabot read scope, or there is a repo-setting gap. Either way this session cannot itself confirm or triage the 3 alerts, and this is unrelated to any of the work-loop items in flight, so filing rather than fixing.

Proposed work

Acceptance criteria

  • The 3 high-severity Dependabot alerts are identified by name/package.
  • Each is remediated (dependency bump) or dismissed with a recorded reason.
  • If the gh api read gap was a token/scope issue rather than zero-alerts, note the fix for future automated checks.

References

Metadata

Work-class: unclassified -- self-filed raw intake, security-surface, routing left to triage. Path/topic hard gate applies (security-critical surface) -- this is filed, not worked, by this lane. 🤖

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: securitySecurity-relevant: vulnerability, hardening, or disclosure follow-up.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions