You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Security
Git dependency hardening: upgrade the runtime GitPython floor and frozen
graph from 3.1.58 to 3.1.61, closing CVE-2026-78675 through CVE-2026-78678
while avoiding the follow-on security and compatibility regressions in 3.1.59
and 3.1.60.
Frozen security tooling: upgrade Semgrep to 1.175.0 and MCP to 1.29.0,
remove the superseded MCP vulnerability exception, and enforce both reviewed
security floors before synchronization.
Release workflow isolation: disable persistent Python and Requirements
Code Review caches, make the compatibility fixture schedule-only, and verify
its immutable commit and tree before exporting its path.
Review dependency boundaries: authenticate the isolated Code Review lock
against its source input and restrict its Pylint license exception to that
exact environment.
Requirements proof authority: re-execute the base-authenticated proof plan
on the fresh consumer and reconcile only consumer-generated JUnit.