Skip to content

Weekly audit refresh: 34811804036 - #63

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
chore/weekly-audit-refresh
Open

github-actions[bot] wants to merge 1 commit into
mainfrom
chore/weekly-audit-refresh

Conversation

@github-actions

@github-actions github-actions Bot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

CVE delta

Net change

Severity Added Removed Net
Critical 7 0 +7
High 253 8 +245
Medium 1131 9 +1122
Low 49 0 +49

Changed images: 36 of 44

Per-image detail

adguard-adguardhome-v0.107.76

  • Added: C:0 H:0 M:2 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-56855 (MEDIUM) — golang.org/x/crypto
      • CVE-2026-78662 (MEDIUM) — golang.org/x/crypto

baserow-baserow-2.2.2

  • Added: C:0 H:6 M:19 L:5
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-74860 (HIGH) — libxml2
      • CVE-2026-84445 (HIGH) — google.golang.org/grpc
      • CVE-2026-86140 (HIGH) — libxml2
      • CVE-2026-86145 (HIGH) — libpcre2-8-0
      • CVE-2026-89161 (HIGH) — libpcre2-8-0
      • GHSA-j95f-988m-3j2f (HIGH) — @tiptap/core
      • CVE-2026-13608 (MEDIUM) — curl
      • CVE-2026-18924 (MEDIUM) — curl
      • ...and 22 more

deluan-navidrome-0.61.2

  • Added: C:0 H:0 M:2 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-56855 (MEDIUM) — golang.org/x/crypto
      • CVE-2026-78662 (MEDIUM) — golang.org/x/crypto

docker.io-caddy-2.11.3

  • Added: C:0 H:1 M:10 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-84445 (HIGH) — google.golang.org/grpc
      • CVE-2026-13608 (MEDIUM) — curl
      • CVE-2026-18924 (MEDIUM) — curl
      • CVE-2026-19931 (MEDIUM) — curl
      • CVE-2026-56855 (MEDIUM) — golang.org/x/crypto
      • CVE-2026-78662 (MEDIUM) — golang.org/x/crypto
      • CVE-2026-80229 (MEDIUM) — curl
      • CVE-2026-80230 (MEDIUM) — curl
      • ...and 3 more

docker.io-library-postgres-18.4-alpine3.23

  • Added: C:0 H:0 M:7 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-13608 (MEDIUM) — libcurl
      • CVE-2026-18924 (MEDIUM) — libcurl
      • CVE-2026-19931 (MEDIUM) — libcurl
      • CVE-2026-80229 (MEDIUM) — libcurl
      • CVE-2026-80230 (MEDIUM) — libcurl
      • CVE-2026-80255 (MEDIUM) — libcurl
      • CVE-2026-82209 (MEDIUM) — libcurl

docker.io-louislam-uptime-kuma-2.3.2

  • Added: C:2 H:28 M:76 L:9
  • Removed: C:0 H:0 M:2 L:0
    • [NEW]:
      • CVE-2026-87534 (CRITICAL) — chromium
      • CVE-2026-87544 (CRITICAL) — chromium
      • CVE-2026-69222 (HIGH) — liquidjs
      • CVE-2026-74860 (HIGH) — libxml2
      • CVE-2026-78899 (HIGH) — chromium
      • CVE-2026-78939 (HIGH) — chromium
      • CVE-2026-79013 (HIGH) — chromium
      • CVE-2026-79066 (HIGH) — chromium
      • ...and 107 more
    • [FIXED]:
      • CVE-2026-14330 (MEDIUM) — libpulse0
      • GHSA-hcpx-6fm6-wx23 (MEDIUM) — axios

docker.io-mariadb-12.2.2

  • Added: C:0 H:0 M:9 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-15534 (MEDIUM) — libperl5.38t64
      • CVE-2026-19487 (MEDIUM) — libperl5.38t64
      • CVE-2026-19499 (MEDIUM) — libc-bin
      • CVE-2026-19542 (MEDIUM) — libc-bin
      • CVE-2026-6368 (MEDIUM) — libc-bin
      • CVE-2026-6791 (MEDIUM) — libc-bin
      • CVE-2026-77117 (MEDIUM) — libc-bin
      • CVE-2026-80489 (MEDIUM) — libc-bin
      • ...and 1 more

docker.io-mongo-8.3.2

  • Added: C:0 H:1 M:16 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-84375 (HIGH) — js-yaml
      • CVE-2026-13608 (MEDIUM) — libcurl4t64
      • CVE-2026-15534 (MEDIUM) — perl-base
      • CVE-2026-18924 (MEDIUM) — libcurl4t64
      • CVE-2026-19487 (MEDIUM) — perl-base
      • CVE-2026-19499 (MEDIUM) — libc-bin
      • CVE-2026-19542 (MEDIUM) — libc-bin
      • CVE-2026-19931 (MEDIUM) — libcurl4t64
      • ...and 9 more

docuseal-docuseal-3.0.0

  • Added: C:0 H:0 M:7 L:0
  • Removed: C:0 H:0 M:1 L:0
    • [NEW]:
      • CVE-2026-13608 (MEDIUM) — libcurl
      • CVE-2026-18924 (MEDIUM) — libcurl
      • CVE-2026-19931 (MEDIUM) — libcurl
      • CVE-2026-80229 (MEDIUM) — libcurl
      • CVE-2026-80230 (MEDIUM) — libcurl
      • CVE-2026-80255 (MEDIUM) — libcurl
      • CVE-2026-82209 (MEDIUM) — libcurl
    • [FIXED]:
      • CVE-2026-14681 (MEDIUM) — libpq

fnsys-dockhand-v1.0.29

  • Added: C:0 H:2 M:8 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-84375 (HIGH) — js-yaml
      • GHSA-2x7j-588g-ccc2 (HIGH) — nodemailer
      • CVE-2026-53495 (MEDIUM) — docker-cli-buildx
      • CVE-2026-56855 (MEDIUM) — docker-cli-buildx
      • CVE-2026-78662 (MEDIUM) — docker-cli-buildx
      • CVE-2026-82209 (MEDIUM) — curl
      • CVE-2026-85091 (MEDIUM) — zlib
      • GHSA-8m3c-c648-2xjj (MEDIUM) — nodemailer
      • ...and 2 more

freshrss-freshrss-1.29.1-alpine

  • Added: C:0 H:0 M:7 L:0
  • Removed: C:0 H:0 M:1 L:0
    • [NEW]:
      • CVE-2026-13608 (MEDIUM) — libcurl
      • CVE-2026-18924 (MEDIUM) — libcurl
      • CVE-2026-19931 (MEDIUM) — libcurl
      • CVE-2026-80229 (MEDIUM) — libcurl
      • CVE-2026-80230 (MEDIUM) — libcurl
      • CVE-2026-80255 (MEDIUM) — libcurl
      • CVE-2026-82209 (MEDIUM) — libcurl
    • [FIXED]:
      • CVE-2026-14681 (MEDIUM) — libpq

ghcr.io-goauthentik-server-2026.2.3

  • Added: C:0 H:98 M:375 L:14
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-74860 (HIGH) — libxml2
      • CVE-2026-80726 (HIGH) — linux-libc-dev
      • CVE-2026-80935 (HIGH) — linux-libc-dev
      • CVE-2026-80937 (HIGH) — linux-libc-dev
      • CVE-2026-80938 (HIGH) — linux-libc-dev
      • CVE-2026-80941 (HIGH) — linux-libc-dev
      • CVE-2026-80942 (HIGH) — linux-libc-dev
      • CVE-2026-80943 (HIGH) — linux-libc-dev
      • ...and 479 more

ghcr.io-open-webui-open-webui-0.9.5

  • Added: C:3 H:101 M:306 L:8
  • Removed: C:0 H:8 M:2 L:0
    • [NEW]:
      • CVE-2026-78676 (CRITICAL) — GitPython
      • CVE-2026-78683 (CRITICAL) — nltk
      • CVE-2026-79657 (CRITICAL) — nltk
      • CVE-2026-62385 (HIGH) — nltk
      • CVE-2026-63312 (HIGH) — nltk
      • CVE-2026-67322 (HIGH) — GitPython
      • CVE-2026-67323 (HIGH) — GitPython
      • CVE-2026-67325 (HIGH) — GitPython
      • ...and 410 more
    • [FIXED]:
      • CVE-2026-64831 (HIGH) — ffmpeg
      • GHSA-2f96-g7mh-g2hx (HIGH) — GitPython
      • GHSA-4gmw-gg2m-w46p (HIGH) — GitPython
      • GHSA-956x-8gvw-wg5v (HIGH) — GitPython
      • GHSA-9rj7-rf2p-w77r (HIGH) — GitPython
      • GHSA-hmq2-w58f-27jc (HIGH) — GitPython
      • GHSA-rwj8-pgh3-r573 (HIGH) — GitPython
      • GHSA-wvpp-8hx9-p66j (HIGH) — GitPython
      • ...and 2 more

ghcr.io-stoatchat-api-v0.13.6

  • Added: C:0 H:0 M:1 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-89092 (MEDIUM) — libc6

ghcr.io-stoatchat-crond-v0.13.6

  • Added: C:0 H:0 M:1 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-89092 (MEDIUM) — libc6

ghcr.io-stoatchat-events-v0.13.6

  • Added: C:0 H:0 M:1 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-89092 (MEDIUM) — libc6

ghcr.io-stoatchat-file-server-v0.13.6

  • Added: C:0 H:0 M:1 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-89092 (MEDIUM) — libc6

ghcr.io-stoatchat-gifbox-v0.13.6

  • Added: C:0 H:0 M:1 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-89092 (MEDIUM) — libc6

ghcr.io-stoatchat-livekit-server-v1.9.13

  • Added: C:0 H:1 M:3 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-84445 (HIGH) — google.golang.org/grpc
      • CVE-2026-56855 (MEDIUM) — golang.org/x/crypto
      • CVE-2026-78662 (MEDIUM) — golang.org/x/crypto
      • CVE-2026-84303 (MEDIUM) — google.golang.org/grpc

ghcr.io-stoatchat-proxy-v0.13.6

  • Added: C:0 H:0 M:1 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-89092 (MEDIUM) — libc6

ghcr.io-stoatchat-pushd-v0.13.6

  • Added: C:0 H:0 M:1 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-89092 (MEDIUM) — libc6

ghcr.io-stoatchat-voice-ingress-v0.13.6

  • Added: C:0 H:0 M:1 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-89092 (MEDIUM) — libc6

ghcr.io-wg-easy-wg-easy-15.3.0

  • Added: C:0 H:0 M:2 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-56855 (MEDIUM) — golang.org/x/crypto
      • CVE-2026-78662 (MEDIUM) — golang.org/x/crypto

ghcr.io-ylianst-meshcentral-1.1.59-mongodb

  • Added: C:0 H:0 M:7 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-13608 (MEDIUM) — curl
      • CVE-2026-18924 (MEDIUM) — curl
      • CVE-2026-19931 (MEDIUM) — curl
      • CVE-2026-80229 (MEDIUM) — curl
      • CVE-2026-80230 (MEDIUM) — curl
      • CVE-2026-80255 (MEDIUM) — curl
      • CVE-2026-82209 (MEDIUM) — curl

ghcr.io-zulip-zulip-server-12.0-0

  • Added: C:1 H:1 M:164 L:0
  • Removed: C:0 H:0 M:1 L:0
    • [NEW]:
      • CVE-2026-37004 (CRITICAL) — litellm
      • CVE-2026-84445 (HIGH) — google.golang.org/grpc
      • CVE-2025-29769 (MEDIUM) — libvips-tools
      • CVE-2026-12773 (MEDIUM) — litellm
      • CVE-2026-13608 (MEDIUM) — curl
      • CVE-2026-15308 (MEDIUM) — libpython3.12-dev
      • CVE-2026-15534 (MEDIUM) — libperl5.38t64
      • CVE-2026-18924 (MEDIUM) — curl
      • ...and 158 more
    • [FIXED]:
      • CVE-2015-8553 (MEDIUM) — linux-libc-dev

lscr.io-linuxserver-jellyfin-10.11.9

  • Added: C:0 H:0 M:14 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-13608 (MEDIUM) — curl
      • CVE-2026-15534 (MEDIUM) — perl-base
      • CVE-2026-18924 (MEDIUM) — curl
      • CVE-2026-19487 (MEDIUM) — perl-base
      • CVE-2026-19499 (MEDIUM) — libc-bin
      • CVE-2026-19542 (MEDIUM) — libc-bin
      • CVE-2026-19931 (MEDIUM) — curl
      • CVE-2026-6368 (MEDIUM) — libc-bin
      • ...and 6 more

mongo-8.3.2

  • Added: C:0 H:1 M:16 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-84375 (HIGH) — js-yaml
      • CVE-2026-13608 (MEDIUM) — libcurl4t64
      • CVE-2026-15534 (MEDIUM) — perl-base
      • CVE-2026-18924 (MEDIUM) — libcurl4t64
      • CVE-2026-19487 (MEDIUM) — perl-base
      • CVE-2026-19499 (MEDIUM) — libc-bin
      • CVE-2026-19542 (MEDIUM) — libc-bin
      • CVE-2026-19931 (MEDIUM) — libcurl4t64
      • ...and 9 more

n8nio-runners-2.22.1

  • Added: C:0 H:0 M:1 L:0
  • Removed: C:0 H:0 M:1 L:0
    • [NEW]:
      • CVE-2026-67321 (MEDIUM) — axios
    • [FIXED]:
      • GHSA-hcpx-6fm6-wx23 (MEDIUM) — axios

nextcloud-33.0.3-fpm-alpine

  • Added: C:0 H:8 M:21 L:8
  • Removed: C:0 H:0 M:1 L:0
    • [NEW]:
      • CVE-2026-49218 (HIGH) — imagemagick
      • CVE-2026-53460 (HIGH) — imagemagick
      • CVE-2026-53461 (HIGH) — imagemagick
      • CVE-2026-61857 (HIGH) — imagemagick
      • CVE-2026-61861 (HIGH) — imagemagick
      • CVE-2026-61863 (HIGH) — imagemagick
      • CVE-2026-61866 (HIGH) — imagemagick
      • CVE-2026-61870 (HIGH) — imagemagick
      • ...and 29 more
    • [FIXED]:
      • CVE-2026-14681 (MEDIUM) — libpq

nginx-1.31.0-alpine3.23

  • Added: C:0 H:0 M:7 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-13608 (MEDIUM) — curl
      • CVE-2026-18924 (MEDIUM) — curl
      • CVE-2026-19931 (MEDIUM) — curl
      • CVE-2026-80229 (MEDIUM) — curl
      • CVE-2026-80230 (MEDIUM) — curl
      • CVE-2026-80255 (MEDIUM) — curl
      • CVE-2026-82209 (MEDIUM) — curl

postgres-18.4

  • Added: C:0 H:4 M:9 L:5
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-74860 (HIGH) — libxml2
      • CVE-2026-86140 (HIGH) — libxml2
      • CVE-2026-86145 (HIGH) — libpcre2-8-0
      • CVE-2026-89161 (HIGH) — libpcre2-8-0
      • CVE-2026-19487 (MEDIUM) — libperl5.40
      • CVE-2026-86138 (MEDIUM) — libxml2
      • CVE-2026-86139 (MEDIUM) — libxml2
      • CVE-2026-86142 (MEDIUM) — libxml2
      • ...and 10 more

qbittorrentofficial-qbittorrent-nox-5.2.0-1

  • Added: C:0 H:0 M:7 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-13608 (MEDIUM) — curl
      • CVE-2026-18924 (MEDIUM) — curl
      • CVE-2026-19931 (MEDIUM) — curl
      • CVE-2026-80229 (MEDIUM) — curl
      • CVE-2026-80230 (MEDIUM) — curl
      • CVE-2026-80255 (MEDIUM) — curl
      • CVE-2026-82209 (MEDIUM) — curl

rabbitmq-4.3.0

  • Added: C:0 H:0 M:9 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-15534 (MEDIUM) — perl-base
      • CVE-2026-19487 (MEDIUM) — perl-base
      • CVE-2026-19499 (MEDIUM) — libc-bin
      • CVE-2026-19542 (MEDIUM) — libc-bin
      • CVE-2026-6368 (MEDIUM) — libc-bin
      • CVE-2026-6791 (MEDIUM) — libc-bin
      • CVE-2026-77117 (MEDIUM) — libc-bin
      • CVE-2026-80489 (MEDIUM) — libc-bin
      • ...and 1 more

syncthing-syncthing-2.1.0

  • Added: C:0 H:0 M:9 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-13608 (MEDIUM) — curl
      • CVE-2026-18924 (MEDIUM) — curl
      • CVE-2026-19931 (MEDIUM) — curl
      • CVE-2026-56855 (MEDIUM) — golang.org/x/crypto
      • CVE-2026-78662 (MEDIUM) — golang.org/x/crypto
      • CVE-2026-80229 (MEDIUM) — curl
      • CVE-2026-80230 (MEDIUM) — curl
      • CVE-2026-80255 (MEDIUM) — curl
      • ...and 1 more

towfiqi-serpbear-3.1.0

  • Added: C:1 H:1 M:3 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • GHSA-2xp9-vwfh-vxw4 (CRITICAL) — next
      • GHSA-2x7j-588g-ccc2 (HIGH) — nodemailer
      • GHSA-8m3c-c648-2xjj (MEDIUM) — nodemailer
      • GHSA-cc9r-2j5m-2m83 (MEDIUM) — nodemailer
      • GHSA-wmmp-3585-3rmp (MEDIUM) — nodemailer

vaultwarden-server-1.36.0-alpine

  • Added: C:0 H:0 M:7 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-13608 (MEDIUM) — curl
      • CVE-2026-18924 (MEDIUM) — curl
      • CVE-2026-19931 (MEDIUM) — curl
      • CVE-2026-80229 (MEDIUM) — curl
      • CVE-2026-80230 (MEDIUM) — curl
      • CVE-2026-80255 (MEDIUM) — curl
      • CVE-2026-82209 (MEDIUM) — curl

@github-actions
github-actions Bot enabled auto-merge (squash) June 15, 2026 07:46
@github-actions github-actions Bot changed the title Weekly audit refresh: 27531642510 Weekly audit refresh: 27937554468 Jun 22, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch 2 times, most recently from b731738 to ee0b4cb Compare June 29, 2026 07:31
@github-actions github-actions Bot changed the title Weekly audit refresh: 27937554468 Weekly audit refresh: 28355862242 Jun 29, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from ee0b4cb to f74a280 Compare July 6, 2026 07:24
@github-actions github-actions Bot changed the title Weekly audit refresh: 28355862242 Weekly audit refresh: 28774870590 Jul 6, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from f74a280 to dd640f5 Compare July 13, 2026 08:41
@github-actions github-actions Bot changed the title Weekly audit refresh: 28774870590 Weekly audit refresh: 29236242866 Jul 13, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from dd640f5 to bf5d844 Compare July 20, 2026 08:33
@github-actions github-actions Bot changed the title Weekly audit refresh: 29236242866 Weekly audit refresh: 29728216532 Jul 20, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from bf5d844 to 816e6d7 Compare July 27, 2026 09:22
@github-actions github-actions Bot changed the title Weekly audit refresh: 29728216532 Weekly audit refresh: 30253527123 Jul 27, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from 816e6d7 to 9cf054d Compare August 3, 2026 08:56
@github-actions github-actions Bot changed the title Weekly audit refresh: 30253527123 Weekly audit refresh: 30799210887 Aug 3, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from 9cf054d to ac8c576 Compare August 10, 2026 06:23
@github-actions github-actions Bot changed the title Weekly audit refresh: 30799210887 Weekly audit refresh: 31361726896 Aug 10, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from ac8c576 to 0cab591 Compare August 17, 2026 06:06
@github-actions github-actions Bot changed the title Weekly audit refresh: 31361726896 Weekly audit refresh: 32000254350 Aug 17, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from 0cab591 to 2cc93c5 Compare August 24, 2026 06:08
@github-actions github-actions Bot changed the title Weekly audit refresh: 32000254350 Weekly audit refresh: 32696049090 Aug 24, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from 2cc93c5 to 8ac450e Compare August 31, 2026 06:03
@github-actions github-actions Bot changed the title Weekly audit refresh: 32696049090 Weekly audit refresh: 33362608869 Aug 31, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from 8ac450e to a8821af Compare September 7, 2026 06:03
@github-actions github-actions Bot changed the title Weekly audit refresh: 33362608869 Weekly audit refresh: 34089089538 Sep 7, 2026
@wn-mira-org

wn-mira-org Bot commented Sep 7, 2026

Copy link
Copy Markdown

Mira PR Walkthrough

Refreshes AUDIT.md for the weekly vulnerability audit without changing application code or dependencies. The PR description reports finding changes across 36 of 44 images, with net increases of 7 critical, 245 high, 1,122 medium, and 49 low findings; this update records audit results rather than remediating vulnerabilities.

Confidence: 4/5   ◉◉◉◉○   Low risk; verify content
  • Only audit documentation changes, so runtime risk is minimal, but the actual diff was not supplied to verify the refreshed content.

1 file reviewed


Comment @wn-mira-org help to get the list of available commands and usage tips.

@wn-mira-org wn-mira-org Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mira Review Summary

The audit refresh updates timestamps without updating the report to include the vulnerability delta described in the PR.

Key Issues

Issue Location
🔴 The new scan metadata labels an unchanged report despite the vulnerability changes reported in the PR description. AUDIT.md:5

Comment thread AUDIT.md Outdated
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from a8821af to e94ad9d Compare September 14, 2026 06:03
@github-actions github-actions Bot changed the title Weekly audit refresh: 34089089538 Weekly audit refresh: 34811804036 Sep 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant