Dependency Security Monitor

Durable reports produced by .github/workflows/dependency-security-monitor.md in github/gh-aw-firewall.

standalone

.github/workflows/dependency-security-monitor.md

View authored workflow

Reports

0 Open 11 Resolved

[Deps] Safe dependency updates (2026-08-26)

Automated Safe Dependency Updates This PR contains safe patch-level dependency updates that have been verified to pass tests and have no breaking changes. Updated Dependencies | Package | Previous | Updated | Type | |---------|----------|---------|------| | js-yaml | 5.2.3 | 5.4.0 | patch | | @typescript-eslint/eslint-plugin | 8.66.0 | 8.68.0 | patch | | @typescript-eslint/parser | 8.66.0 | 8.68.0 | patch | | typescript-eslint | 8.66.0 | 8.68.0 | patch | Security Fixes Included No CVEs were addressed — npm audit reported 0 vulnerabilities and Dependabot alerts were inaccessible to this workflow's token (403). These are routine patch-level freshness updates. Verification [x] npm audit — 0 ...

closed review issue

[Deps] Safe dependency updates (2026-08-25)

Automated Safe Dependency Updates This PR contains safe patch-level dependency updates verified to pass build, lint, and (pre-existing-failure-adjusted) tests. Updated Dependencies | Package | Previous | Updated | Type | |---------|----------|---------|------| | eslint | 10.9.0 | 10.9.1 | patch | | @typescript-eslint/eslint-plugin | 8.67.0 | 8.68.0 | patch | | @typescript-eslint/parser | 8.67.0 | 8.68.0 | patch | | typescript-eslint | 8.67.0 | 8.68.0 | patch | Security Fixes Included None — npm audit reported 0 vulnerabilities at time of this run, and Dependabot alerts were not accessible with the current token (403, missing securityevents scope). No HIGH/CRITICAL CVEs were found requirin...

closed review issue

[Deps] Safe dependency updates (2026-08-22)

Automated Safe Dependency Updates This PR contains safe patch-level dependency updates verified to pass the test suite and build. Updated Dependencies | Package | Previous | Updated | Type | |---------|----------|---------|------| | eslint | ^10.8.0 | ^10.9.0 | patch | Security Fixes Included None — npm audit reported 0 vulnerabilities and no open Dependabot alerts were accessible/found. This is a routine patch-level freshness update. Verification [x] npm run build passes [x] npm test passes (308/311 suites; the 3 pre-existing failures in src/enclave/mount-policy.test.ts and related files reproduce identically on main without this change — they stem from /var/tmp not existing in this sand...

closed review issue

[aw] Dependency Security Monitor failed

Workflow Failure Workflow: Dependency Security Monitor Branch: main Run: https://github.com/github/gh-aw-firewall/actions/runs/32210085773 [!WARNING] Engine Failure: The copilot engine terminated unexpectedly. Last agent output: Action Required Assign this issue to an agent to debug and fix the issue. <details> <summary>Debug with any coding agent</summary> Use this prompt with any coding agent (GitHub Copilot, Claude, Gemini, etc.): </details> <details> <summary>Manually invoke the agent</summary> Debug this workflow failure using your favorite Agent CLI and the agentic-workflows prompt. Start your agent Load the agentic-workflows skill from .github/skills/agentic-workflows/SKILL.md or <...

closed live issue

[Deps] Safe dependency updates (2026-08-16)

Automated Safe Dependency Updates This PR contains safe patch/minor-level dependency updates resolved within existing package.json semver ranges (via npm update), verified to: ✅ npm audit reports 0 vulnerabilities (before and after) ✅ Pass the full test suite (aside from 3 pre-existing failures unrelated to these changes — see below) ✅ No package.json range changes — only package-lock.json resolved versions bumped Updated Dependencies (package-lock.json only) | Package | Type | |---------|------| | js-yaml | patch (5.2.3 → 5.3.0) | | esbuild | patch (0.28.1 → 0.28.2) | | eslint | patch (10.8.0 → 10.8.1) | | globals | minor (17.9.0 → 17.11.0) | | @typescript-eslint/eslint-plugin | patch (8...

closed review issue

[aw] Dependency Security Monitor is missing required tool

Workflow Failure Workflow: Dependency Security Monitor Branch: main Run: https://github.com/github/gh-aw-firewall/actions/runs/31989352830 [!WARNING] Missing Tools Reported: The agent reported missing tools during execution. Missing Tools: list\dependabot\alerts / get\dependabot\alert: Dependabot alerts API returned 403 \(token lacks security\events scope\) so alerts could not be cross-checked with npm audit findings. Alternatives: | Tool | Alternative | | --- | --- | | list\dependabot\alerts / get\dependabot\alert | Grant security\events/Dependabot read permission to the workflow token, or run 'gh api /repos/github/gh-aw-firewall/dependabot/alerts' with a PAT that has this scope. | Actio...

closed review issue

[aw] Dependency Security Monitor failed

Workflow Failure Workflow: Dependency Security Monitor Branch: main Run: https://github.com/github/gh-aw-firewall/actions/runs/31860264911 [!WARNING] Engine Failure: The copilot engine terminated unexpectedly. Last agent output: Action Required Assign this issue to an agent to debug and fix the issue. <details> <summary>Debug with any coding agent</summary> Use this prompt with any coding agent (GitHub Copilot, Claude, Gemini, etc.): </details> <details> <summary>Manually invoke the agent</summary> Debug this workflow failure using your favorite Agent CLI and the agentic-workflows prompt. Start your agent Load the agentic-workflows skill from .github/skills/agentic-workflows/SKILL.md or <...

closed live issue

[aw] Dependency Security Monitor is missing required tool

Workflow Failure Workflow: Dependency Security Monitor Branch: main Run: https://github.com/github/gh-aw-firewall/actions/runs/31291851630 [!WARNING] Missing Tools Reported: The agent reported missing tools during execution. Missing Tools: list\dependabot\alerts / get\dependabot\alert: Dependabot alerts API returned 403 \(token lacks security\events scope\), so Dependabot alerts could not be cross-checked for this run. Alternatives: | Tool | Alternative | | --- | --- | | list\dependabot\alerts / get\dependabot\alert | Grant the workflow token 'security\events' scope, or run npm audit + manual Dependabot dashboard review as a fallback \(done for this run via npm audit\). | Action Required ...

closed review issue

[Deps] Safe dependency updates (2026-08-08)

Automated Safe Dependency Updates This PR contains safe patch-level dependency updates verified to pass the test suite and introduce no breaking changes. Updated Dependencies | Package | Previous | Updated | Type | |---------|----------|---------|------| | eslint | 10.8.0 | 10.8.1 | patch | | globals | 17.8.0 | 17.9.0 | patch | | js-yaml | 5.2.2 | 5.2.3 | patch | | @typescript-eslint/eslint-plugin | 8.65.0 | 8.66.0 | patch | | @typescript-eslint/parser | 8.65.0 | 8.66.0 | patch | | typescript-eslint | 8.65.0 | 8.66.0 | patch | Security Fixes Included None — npm audit reported 0 vulnerabilities before and after this change. Dependabot alerts could not be queried (token lacks securityevents...

closed review issue

[Deps] Safe dependency updates (2026-07-31)

Automated Safe Dependency Updates This PR contains safe patch-level dependency updates that have been verified to pass all tests (no new failures introduced) and have no breaking changes. Updated Dependencies | Package | Previous | Updated | Type | |---------|----------|---------|------| | globals | 17.7.0 | 17.8.0 | patch | | markdownlint-cli2 | 0.23.1 | 0.23.2 | patch | Security Fixes Included None — npm audit reported 0 vulnerabilities (0 critical/high/moderate/low) across all 651 dependencies at the time of this run. GitHub Dependabot alerts could not be checked in this run because the workflow token lacks securityevents/Dependabot-alerts read permission for this repository (403 respo...

closed review issue

[Deps] Safe dependency updates (2026-07-28)

Automated Safe Dependency Updates This PR contains safe patch-level dependency updates that have been verified to: ✅ Pass all tests (4124 tests, 255 suites) ✅ No breaking changes ✅ No security vulnerabilities found (npm audit: 0 vulnerabilities) Updated Dependencies | Package | Previous | Updated | Type | |---------|----------|---------|------| | globals | 17.7.0 | 17.8.0 | patch | | markdownlint-cli2 | 0.23.1 | 0.23.2 | patch | Security Status npm audit: 0 vulnerabilities (0 critical, 0 high, 0 moderate, 0 low) Dependabot alerts: Access not available via workflow token Verification [x] All 4124 tests pass across 255 test suites [x] No breaking changes detected Skipped Updates (major vers...

closed review issue