Skip to content

Fix reported dependency vulnerabilities - #86

Merged
johnnygreco merged 1 commit into
mainfrom
johnny/security-report-remediation
Sep 29, 2026
Merged

johnnygreco merged 1 commit into
mainfrom
johnny/security-report-remediation

Conversation

@johnnygreco

Copy link
Copy Markdown
Collaborator

Summary

  • Raise the Reachy project's anyio and cryptography minimums to the report's patched versions and regenerate uv.lock.
  • Document the Go golang.org/x/crypto advisory as an unfixed openpgp package finding; the exporter's compiled dependency graph does not include openpgp.

Validation

  • uv lock --check — passed.
  • go mod verify — passed.
  • go vet ./... — passed.
  • go build ./cmd/... — passed.
  • go test -race -p 1 ./... — passed.
  • Reachy test suite — unavailable on this Linux host because the committed lock supports macOS only.

The attached report does not include advisory IDs. The Go assessment is based on the published GO-2026-5932 advisory and go list -deps ./....

@johnnygreco
johnnygreco merged commit df5e21a into main Sep 29, 2026
13 checks passed
@johnnygreco
johnnygreco deleted the johnny/security-report-remediation branch September 29, 2026 02:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant