Skip to content

chore(deps): resolve OSV scanner findings - #180

Merged
jdomeracki-coder merged 2 commits into
mainfrom
fix/osv-scanner-vulnerabilities
Sep 16, 2026
Merged

jdomeracki-coder merged 2 commits into
mainfrom
fix/osv-scanner-vulnerabilities

Conversation

@jdomeracki-coder

Copy link
Copy Markdown
Contributor

The scheduled OSV scan reports one fixable transitive DHCP vulnerability and several findings in packages whose affected code envbox does not import.

Update github.com/insomniacslk/dhcp to its fixed revision and add documented OSV exceptions for Docker CLI Windows plugin discovery, Docker daemon-only code, runc device setup, and the deprecated x/crypto/openpgp package.

Refs https://github.com/coder/envbox/actions/runs/34829845489

Coder Agents disclosure

This pull request was generated by Coder Agents.

@jdomeracki-coder
jdomeracki-coder marked this pull request as ready for review September 14, 2026 10:44
@jdomeracki-coder
jdomeracki-coder merged commit b294406 into main Sep 16, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants