awf v0.5.1
A patch release that clears resolvable dependency advisories. No functional
changes to the tool.
Security
- Dependency bumps clearing 11 of 20 Dependabot advisories, including the
sole critical. Go:containerd/v22.1.5 → 2.1.9 (5 advisories) and
in-toto-golang0.9.0 → 0.11.0 (1). UI dev tooling:vite5 → 6.4.3 and
vitest2 → 3.2.6 (5, including the criticalvitestUI-server file-read;
these packages are build-time only and never ship in theawfbinary). The
nine remaining advisories are all in the Docker/Moby client chain and are
either unfixed upstream or blocked on the Docker v29 /moby/mobymigration
thatdocker/composehas not yet adopted; SECURITY.md tracks
each one and why it is still present.