Skip to content

click 'enter' to submit message#168

Merged
Gkrumbach07 merged 1 commit intoambient-code:mainfrom
MichaelClifford:message
Oct 11, 2025
Merged

click 'enter' to submit message#168
Gkrumbach07 merged 1 commit intoambient-code:mainfrom
MichaelClifford:message

Conversation

@MichaelClifford
Copy link
Copy Markdown
Contributor

No description provided.

Signed-off-by: Michael Clifford <mcliffor@redhat.com>
@cooktheryan
Copy link
Copy Markdown
Contributor

@Gkrumbach07 can you merge this if you are ok with it

@Gkrumbach07 Gkrumbach07 merged commit bd01214 into ambient-code:main Oct 11, 2025
10 of 11 checks passed
sallyom pushed a commit that referenced this pull request Oct 15, 2025
@bobbravo2 bobbravo2 added this to the v0.0.3 milestone Jan 30, 2026
jeremyeder added a commit that referenced this pull request Apr 10, 2026
## Summary

- Bump `next` 16.2.2 → 16.2.3 — fixes DoS via Server Components (alert
#173)
- Bump `aiohttp` ≥3.13.3 → ≥3.13.4 — fixes 9 CVEs: header injection,
SSRF, DoS, credential leak, CRLF injection (alerts #149–158)
- Bump `cryptography` 46.0.5 → 46.0.7 (transitive) — fixes buffer
overflow (alert #172)
- Bump `lupa` 2.6 → 2.7 (transitive) — fixes sandbox escape / RCE (alert
#168)

### Remaining alerts (3)

Alerts #144, #145, #146 (`fastmcp` 2.14.3 → 3.2.0) are **blocked on
upstream**: `mcp-atlassian` 0.21.1 pins `fastmcp<2.15.0,>=2.13.0`. The
CVEs affect fastmcp's OpenAPI provider and OAuth proxy — not in our code
path, but the alerts will stay open until `mcp-atlassian` releases a
version compatible with fastmcp 3.x.

## Test plan

- [x] Frontend: 614 tests pass (`npx vitest run`)
- [x] Runner: 543 tests pass (`uv run pytest tests/`)
- [ ] CI passes

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Bumped frontend and runtime dependency minimums to newer patch
releases.

* **Refactor**
* Code formatting and parameter/layout reflows across several modules
for readability.

* **Tests**
* Cleaned up and reformatted unit tests, removing unused imports and
improving fixture readability.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ambient Code Bot <bot@ambient-code.local>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants