Skip to content

1.0.0: Security alert fixes: postcss XSS + CodeQL false-positive suppression

Choose a tag to compare

@Dim145 Dim145 released this 20 May 11:44
· 101 commits to main since this release
- Dependabot: Next 16.2.6 transitively pinned postcss@8.4.31 (XSS via
  unescaped </style> in the URL parser, GHSA-7fh5-64p2-3v2j). The direct
  dep was already ^8.5.14, but the override block now forces the
  transitive resolution to ^8.5.14 as well. npm now resolves all
  postcss instances to 8.5.15.
- CodeQL py/weak-sensitive-data-hashing on _hash_api_secret: heuristic
  flagged hashlib.sha256(secret) as a weak password hash. It's a false
  positive — this code path never sees a user password. Inputs are
  256-bit random tokens from secrets.token_urlsafe(32). A slow KDF
  protects against dictionary attacks on low-entropy human input,
  which doesn't apply here, and switching to argon2 would add ~100ms
  per F-Droid client request (50+ requests per index sync). Reinforced
  the in-code rationale and added a `# lgtm [py/weak-sensitive-data-hashing]`
  suppression annotation. Alert #2 dismissed via the API with the same
  justification.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>