You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Updated Claude Code to 2.1.290, OpenSpec to 1.14.1, pnpm to 12.9.1, ESLint to 10.12.0, and Wrangler to 4.147.0 with its matching Miniflare and workerd packages.
Switched GitHub CLI, fzf, and lazygit to official checksum-verified release archives. Updated lazygit to 0.66.0 and delta to 0.20.1.
Kept the full Trivy and Docker Scout reports and added accepted upstream vulnerability records. Third-party findings remain visible; secrets, HolyCode-owned findings, invalid reports, unknown package provenance, and scanner failures still block delivery.
Kept Paperclip at 2026.831.1 and Claude Auth at 2.2.1. The credential-refresh report in issue #11 remains open.
Fixed
Updated all three Debian Chromium packages to .92 on AMD64 and ARM64, fixing the earlier v1.2.4 .57 advisory set and removing its package exception. Newer CVEs remain listed below. Pull coderluii/holycode:1.2.5 and restart your container to apply the update.
Corrected the security-policy audit link, the contribution guide for disabled Discussions, and the missing v1.2.4 changelog entries.
Known issues
Debian Chromium is 154.0.8037.92-1~deb13u1 on AMD64 and ARM64. It fixes the older .57 advisory set, but five newer CVEs remain accepted upstream vulnerabilities: CVE-2026-103622, CVE-2026-103624, CVE-2026-103625, CVE-2026-103626, and CVE-2026-103628. Two are Critical. Google ships the upstream fix in .97; Debian has not published that package yet. Avoid untrusted browser content and automation until the corrected Debian packages ship. See the dependency audit.
Other accepted upstream findings remain listed by dependency, installed version, and CVE in the scanner assets attached to this release. Acceptance permits delivery; it does not mean those findings are fixed.