Skip to content

deps(security): address 1 critical + 2 high Dependabot alerts (vitest, fast-uri, pyo3) #607

Description

@KooshaPari

Dependabot Security Audit (2026-07-15)

Dependabot is now enabled on this repo (alerts + automated security fixes + config in .github/dependabot.yml). Current open alerts: 20 total (1 critical, 2 high, 14 medium, 3 low).

Critical (1)

# Package Summary
#20 vitest When Vitest UI server is listening, arbitrary file can be read and executed

High (2)

# Package Summary
#34 fast-uri Host confusion via percent-encoded authority delimiters
#21 pyo3 Out-of-bounds Read in `nth` / `nth_back` for `PyList` / `PyTuple` iterators

Recommended action

  1. vitest: Bump to `>=3.2.0` (fixed in 3.2.0). Update the `codex-cli` devDependency and any Cargo features that pull vitest.
  2. fast-uri: Transitive — wait for upstream (axios? express?). If this is direct, bump to `>=3.0.6`.
  3. pyo3: Bump to a patched version (>= 0.27 or apply backport per the advisory). Update `helios-cli/codex-rs` Python bindings.

Dependabot will start opening auto-PRs as soon as this config is merged. After this config is merged, this issue can be tracked in the auto-PRs themselves.

Refs:

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions