You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
- Dependabot: Next 16.2.6 transitively pinned postcss@8.4.31 (XSS via
unescaped </style> in the URL parser, GHSA-7fh5-64p2-3v2j). The direct
dep was already ^8.5.14, but the override block now forces the
transitive resolution to ^8.5.14 as well. npm now resolves all
postcss instances to 8.5.15.
- CodeQL py/weak-sensitive-data-hashing on _hash_api_secret: heuristic
flagged hashlib.sha256(secret) as a weak password hash. It's a false
positive — this code path never sees a user password. Inputs are
256-bit random tokens from secrets.token_urlsafe(32). A slow KDF
protects against dictionary attacks on low-entropy human input,
which doesn't apply here, and switching to argon2 would add ~100ms
per F-Droid client request (50+ requests per index sync). Reinforced
the in-code rationale and added a `# lgtm [py/weak-sensitive-data-hashing]`
suppression annotation. Alert #2 dismissed via the API with the same
justification.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>