Skip to content

chore(main): release together-sandbox-workspace 4.0.3 - #130

Merged
mohamedveron merged 1 commit into
mainfrom
release-please--branches--main--components--together-sandbox-workspace
Aug 11, 2026
Merged

chore(main): release together-sandbox-workspace 4.0.3#130
mohamedveron merged 1 commit into
mainfrom
release-please--branches--main--components--together-sandbox-workspace

Conversation

@github-actions

@github-actions github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

🤖 I have created a release beep boop

4.0.3 (2026-08-10)

Bug Fixes

  • extract a human-readable error message from unknown server errors (0a694f7)
  • make base url construction same as typescript (1db7fd3)

This PR was generated with Release Please. See documentation.

@broly-code-security-scanner

broly-code-security-scanner Bot commented Aug 5, 2026

Copy link
Copy Markdown

Broly Security Scan

Note

Summary

9 actionable finding(s) in this PR
13 total in scan · 4 dismissed false positives

  • 🟡 9 medium

5 highest-priority actionable rows in the table below (critical/high first, then top medium).

No finding is at or above high, so this check is not blocking. The findings above are still tracked and reported.

Severity Scanner Issue Location Dismiss Verdict
🟡 MEDIUM SCA tar@6.2.1 — 11 vulnerabilities (worst:
GHSA-23hp-3jrh-7fpw)
→ >= 7.5.8
package-lock.json:1 d7 🔺 TRUE_POSITIVE · Confidence: HIGH
🟡 MEDIUM SCA nanoid@3.3.11 — 2 vulnerabilities (worst:
GHSA-28wg-ghj8-5hjv)
→ >= 3.3.17
package-lock.json:1 d9 🔺 TRUE_POSITIVE · Confidence: HIGH
🟡 MEDIUM SCA handlebars@4.7.8 — 7 vulnerabilities (worst:
GHSA-2w6w-674q-4c4q)
→ >= 4.7.9
package-lock.json:1 d8 🔺 TRUE_POSITIVE · Confidence: HIGH
🟡 MEDIUM SCA brace-expansion@5.0.4 — 5 vulnerabilities
(worst: GHSA-3jxr-9vmj-r5cp)
→ >= 5.0.8
package-lock.json:1 d4 🔺 TRUE_POSITIVE · Confidence: HIGH
🟡 MEDIUM SCA js-yaml@4.1.1 — 3 vulnerabilities (worst:
GHSA-52cp-r559-cp3m)
→ >= 4.3.1
package-lock.json:1 d5 🔺 TRUE_POSITIVE · Confidence: low
🟢 Dismissed false positives (4) — not shown above
  • 🟡 MEDIUM · GHSA-67mh-4wv8-2f99: esbuild@0.21.5 · package-lock.json:1 — esbuild@0.21.5 is a transitive dependency of vite/vitest used only for local development and testing, and is not included in the production runtime image which is built with tsc and ships only runtime dependencies.
  • 🟡 MEDIUM · GHSA-g7r4-m6w7-qqqr: esbuild@0.27.7 · package-lock.json:1 — esbuild 0.27.7 is used only through the tsx devDependency for local TypeScript execution and is not included in production builds where the vulnerable development server would never be exposed.
  • 🟡 MEDIUM · GHSA-5xrq-8626-4rwp: vitest@2.1.9 · package-lock.json:1 — Vitest is a devDependency test runner that is never shipped in the production runtime image, and no source files importing this package were found in scanned paths.
  • 🟡 MEDIUM · vite@5.4.21 — 2 vulnerabilities (worst: GHSA-fx2h-pf6j-xcff) · package-lock.json:1 — vite@5.4.21 is vitest 2's internal dev-only toolchain that never ships to production, where the server is bundled with esbuild and the static client is built by a separate vite 6.4.3.

Dismiss false positives

Tick a box to dismiss the finding; untick it to bring the finding back. That is the same as replying /broly dismiss d1 and /broly undismiss d1. To record why it is a false positive, reply with /broly dismiss d1: your reason instead — Broly reuses those reasons to triage similar findings across the org.

  • d1 · 🟡 MEDIUM   · package-lock.json:1 · GHSA-r5fr-rjxr-66jc: lodash@4.17.23
  • d6 · 🟡 MEDIUM   · package-lock.json:1 · postcss@8.5.8 — 4 vulnerabilities (worst: GHSA-6g55-p6wh-862q)
  • d2 · 🟡 MEDIUM   · package-lock.json:1 · GHSA-r292-9mhp-454m: tar@7.5.20
  • d8 · 🟡 MEDIUM   · package-lock.json:1 · handlebars@4.7.8 — 7 vulnerabilities (worst: GHSA-2w6w-674q-4c4q)
  • d7 · 🟡 MEDIUM   · package-lock.json:1 · tar@6.2.1 — 11 vulnerabilities (worst: GHSA-23hp-3jrh-7fpw)
  • d5 · 🟡 MEDIUM   · package-lock.json:1 · js-yaml@4.1.1 — 3 vulnerabilities (worst: GHSA-52cp-r559-cp3m)
  • d3 · 🟡 MEDIUM   · package-lock.json:1 · GHSA-hhx9-57xq-r5rw: @hey-api/openapi-ts@0.84.4
  • d4 · 🟡 MEDIUM   · package-lock.json:1 · brace-expansion@5.0.4 — 5 vulnerabilities (worst: GHSA-3jxr-9vmj-r5cp)
  • d9 · 🟡 MEDIUM   · package-lock.json:1 · nanoid@3.3.11 — 2 vulnerabilities (worst: GHSA-28wg-ghj8-5hjv)

Note

Re-scan this PR anytime with /broly scan — useful after /broly undismiss, or to refresh findings without a new push.

Broly — SAST (zai-org/GLM-5.2) · Secrets · SCA · IaC · GH Actions · Base Images · Supply Chain Threats · Exploit Chains · Adversarial Verification

We're continuously improving Broly's accuracy and finding quality — your feedback is valuable. False positives, missed findings, bugs, and feature requests all welcome.

Ask in #security-engineering   Powered by Together AI

@github-actions
github-actions Bot force-pushed the release-please--branches--main--components--together-sandbox-workspace branch from 728f123 to 655ec32 Compare August 10, 2026 08:10
@mohamedveron
mohamedveron merged commit 03f60e9 into main Aug 11, 2026
10 checks passed
@github-actions

Copy link
Copy Markdown
Contributor Author

🤖 Created releases:

🌻

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant