Dependabot Security Audit (2026-07-15)
Dependabot is now enabled on this repo (alerts + automated security fixes + config in .github/dependabot.yml). Current open alerts: 20 total (1 critical, 2 high, 14 medium, 3 low).
Critical (1)
| # |
Package |
Summary |
| #20 |
vitest |
When Vitest UI server is listening, arbitrary file can be read and executed |
High (2)
| # |
Package |
Summary |
| #34 |
fast-uri |
Host confusion via percent-encoded authority delimiters |
| #21 |
pyo3 |
Out-of-bounds Read in `nth` / `nth_back` for `PyList` / `PyTuple` iterators |
Recommended action
- vitest: Bump to `>=3.2.0` (fixed in 3.2.0). Update the `codex-cli` devDependency and any Cargo features that pull vitest.
- fast-uri: Transitive — wait for upstream (axios? express?). If this is direct, bump to `>=3.0.6`.
- pyo3: Bump to a patched version (>= 0.27 or apply backport per the advisory). Update `helios-cli/codex-rs` Python bindings.
Dependabot will start opening auto-PRs as soon as this config is merged. After this config is merged, this issue can be tracked in the auto-PRs themselves.
Refs:
Dependabot Security Audit (2026-07-15)
Dependabot is now enabled on this repo (alerts + automated security fixes + config in
.github/dependabot.yml). Current open alerts: 20 total (1 critical, 2 high, 14 medium, 3 low).Critical (1)
High (2)
Recommended action
Dependabot will start opening auto-PRs as soon as this config is merged. After this config is merged, this issue can be tracked in the auto-PRs themselves.
Refs: