-
Notifications
You must be signed in to change notification settings - Fork 0
Description
2026-03-29 (UTC)
Summary Metrics
| Metric | Value |
|---|---|
| New issues (since last run) | 0 |
| Open PRs | 1 (★#405: vitest v4.1.2) |
| Stale issues (>30 days) | 0 |
| Stale PRs (>7 days) | 0 |
| Main branch checks | ✅ CI: success (2026-03-29T15:25:04Z) |
| Security alerts (Dependabot) | 10 open (unchanged since last run) |
Stale Issues (no activity >30 days)
No stale issues. 2 open issues (#252 Daily Maintenance Report, #2 Dependency Dashboard).
Stale PRs (no activity >7 days />14 days)
No stale PRs. The 1 open PR is fresh (opened 2026-03-29).
Unassigned Bugs
No open issues with the bug label.
Recommended Actions
- Address 10 open Dependabot alerts (unchanged):
- Review/merge #405:
chore(dev): update dependency vitest to v4.1.2
Notes
- ★9 PRs merged since last run (2026-03-28 after report):
- #403:
chore(release): pending release v0.34.1 - #404:
build(deps): update dependency @opencode-ai/sdk to v1.3.5 - #402:
build(deps): update dependency anomalyco/opencode to v1.3.5 - #400:
chore(release): pending release v0.34.0 - #399:
build(deps): update dependency anomalyco/opencode to v1.3.4 - #398:
feat(dedup): bypass dedup for synchronize and reopened PR actions - #397:
chore(release): pending release v0.33.0 - #396:
feat(artifact): add direct log artifact upload to action runtime - #395:
ci(deps): update bfra-me/.github to v4.14.3
- #403:
- ★1 new PR opened: #405
chore(dev): update dependency vitest to v4.1.2 - Main branch last commit:
188979b— "build(deps): update dependency @opencode-ai/sdk to v1.3.5" - CI passing on main branch
2026-03-28 (UTC)
Summary Metrics
| Metric | Value |
|---|---|
| New issues (since last run) | 0 |
| Open PRs | 0 (★11 merged since last run) |
| Stale issues (>30 days) | 0 |
| Stale PRs (>7 days) | 0 |
| Main branch checks | ⏳ Fro Bot: in progress (this run) |
| Security alerts (Dependabot) | ★10 open — 5 new critical/high handlebars, 2 picomatch alerts resolved |
Stale Issues (no activity >30 days)
No stale issues. 2 open issues (#252 Daily Maintenance Report, #2 Dependency Dashboard).
Stale PRs (no activity >7 days />14 days)
No stale PRs. No open PRs — all dependency updates have been merged.
Unassigned Bugs
No open issues with the bug label.
Recommended Actions
- ★ Address 10 open Dependabot alerts:
- #52:
handlebars(★CRITICAL - CVE-2026-33937 JavaScript Injection via AST) - #53, #54, #55, #56:
handlebars(★HIGH - CVE-2026-33938/33939/33940/33941) - #47:
handlebars(medium - CVE-2026-33916 Prototype Pollution XSS) - #48:
picomatch(high - CVE-2026-33671 ReDoS) - #49:
picomatch(medium - CVE-2026-33672 Method Injection) - #50, #51:
brace-expansion(medium - CVE-2026-33750 DoS)
- #52:
- Repository is healthy — CI operational, all recent PRs merged
Notes
- ★11 PRs merged since last run (2026-03-27 after report):
- #394:
chore(release): pending release v0.32.3 - #392:
build(dev): update dependency tsdown to v0.21.5 - #393:
fix(session): preserve logical thread continuity - #385:
chore(dev): update dependency vitest to v4.1.1 - #382:
chore(dev): update dependency @vitest/eslint-plugin to v1.6.13 - #388:
ci(deps): update github/codeql-action action to v4.35.1 - #389:
chore(deps): update pnpm to v10.33.0 - #387:
chore(release): pending release v0.32.2 - #391:
build(deps): update dependency @opencode-ai/sdk to v1.3.2 - #390:
build(deps): update dependency oh-my-openagent to v3.14.0 - #384:
build(deps): update dependency @opencode-ai/sdk to v1.3.0
- #394:
- ★Security alerts status changed: 2 picomatch alerts (docs: update to PRD v1.1 with SDK execution model #45, feat(agent): implement RFC-013 SDK execution mode #46) resolved; 5 new handlebars alerts (chore: update markdown lint and eslint to ignore AGENTS.md globally #52-chore: add opencode configuration file #56) opened
- 0 open PRs — all dependency updates successfully merged
- Main branch last commit:
4a950a6— "chore(release): pending release v0.32.3" (chore(release): pending release v0.32.3 #394)
2026-03-27 (UTC)
Summary Metrics
| Metric | Value |
|---|---|
| New issues (since last run) | 0 |
| Open PRs | 4 (★1 new: #387; 3 carried: #385, #384, #382) |
| Stale issues (>30 days) | 0 |
| Stale PRs (>7 days) | 0 |
| Main branch checks | ⏳ Fro Bot: in progress (this run); 13 completed checks |
| Security alerts (Dependabot) | ★7 open — all new: 2 high (picomatch), 5 medium (picomatch x2, handlebars, brace-expansion x2) |
Stale Issues (no activity >30 days)
No stale issues. 2 open issues (#252 Daily Maintenance Report, #2 Dependency Dashboard).
Stale PRs (no activity >7 days />14 days)
No stale PRs. All 4 open PRs are dependency/release updates active within the last 2 days.
Unassigned Bugs
No open issues with the bug label.
Recommended Actions
- ★ Address 7 new Dependabot alerts (opened 2026-03-27):
- Review/merge 4 open PRs:
- #387:
chore(release): pending release v0.32.2(opened today) - #385:
chore(dev): update dependency vitest to v4.1.1(opened yesterday) - #384:
build(deps): update dependency @opencode-ai/sdk to v1.3.0(opened yesterday) - #382:
chore(dev): update dependency @vitest/eslint-plugin to v1.6.13(opened yesterday)
- #387:
Notes
- ★2 PRs merged since last run (2026-03-27):
- ★7 new Dependabot security alerts (all opened 2026-03-27)
- 2 open issues remain unchanged: #252, #2
- Main branch last commit:
ci(deps): update github/codeql-action action to v4.35.0(ci(deps): update github/codeql-action action to v4.35.0 #386)
2026-03-26 (UTC)
Summary Metrics
| Metric | Value |
|---|---|
| New issues (since last run) | 0 |
| Open PRs | 4 (★2 new: #385, #384; 2 carried: #382, #381) |
| Stale issues (>30 days) | 0 |
| Stale PRs (>7 days) | 0 |
| Main branch checks | ⏳ Fro Bot: in progress (this run); Renovate: skipped |
| Security alerts (Dependabot) | ✅ 0 open — all resolved |
Stale Issues (no activity >30 days)
No stale issues. 2 open issues (#252 Daily Maintenance Report, #2 Dependency Dashboard).
Stale PRs (no activity >7 days />14 days)
No stale PRs. All 4 open PRs are dependency updates active within the last 2 days.
Unassigned Bugs
No open issues with the bug label.
Recommended Actions
- Review/merge 4 open Renovate PRs:
- #385:
chore(dev): update dependency vitest to v4.1.1(opened today) - #384:
build(deps): update dependency @opencode-ai/sdk to v1.3.0(opened today) - #382:
chore(dev): update dependency @vitest/eslint-plugin to v1.6.13(opened yesterday) - #381:
build(deps): update dependency anomalyco/opencode to v1.3.3(carried from 2026-03-24)
- #385:
- Repository is healthy — 0 security alerts, CI operational
Notes
- ★2 PRs merged since last run (2026-03-25 after report):
- ★2 new PRs opened today: #385, #384
- Dependency Dashboard #2 shows no CVEs detected
- Main branch last commit:
f9a24e2— "chore(deps): update Node.js to v24.14.1"
2026-03-25 (UTC)
Summary Metrics
| Metric | Value |
|---|---|
| New issues (since last run) | 0 |
| Open PRs | 4 (★3 new: #383, #382, #381; 1 carried: #378) |
| Stale issues (>30 days) | 0 |
| Stale PRs (>7 days) | 0 |
| Main branch checks | ⏳ Fro Bot: in progress (this run); Renovate: skipped |
| Security alerts (Dependabot) | ✅ 0 open — all resolved |
Stale Issues (no activity >30 days)
No stale issues. 2 open issues (#252 Daily Maintenance Report, #2 Dependency Dashboard — updated today).
Stale PRs (no activity >7 days />14 days)
No stale PRs. All 4 open PRs are dependency updates created 2026-03-24–2026-03-25, all active today.
Unassigned Bugs
No open issues with the bug label.
Recommended Actions
- Review/merge 4 open Renovate PRs:
- Repository is healthy — 0 security alerts, CI operational
Notes
- ★3 PRs merged since last run (2026-03-24 after report):
- ★3 new PRs opened today: #383, #382, #381
- ★1 new PR opened yesterday after last report: #378
chore(deps): update Node.js to v24.14.1 - Dependency Dashboard #2 updated today (2026-03-25T11:37:42Z)
- 0 Dependabot security alerts — all clear
2026-03-24 (UTC)
Summary Metrics
| Metric | Value |
|---|---|
| New issues (since last run) | 0 |
| Open PRs | 1 (★#377: ci(deps): update bfra-me/.github to v4.13.8) |
| Stale issues (>30 days) | 0 |
| Stale PRs (>7 days) | 0 |
| Main branch checks | ✅ Scorecard: success (2026-03-24T08:02Z); ✅ CI: success (2026-03-23T19:59Z via #375 merge); ⏳ Fro Bot: in progress |
| Security alerts (Dependabot) | ✅ 0 open — all resolved |
Stale Issues (no activity >30 days)
No stale issues. 2 open issues (#252 Daily Maintenance Report, #2 Dependency Dashboard).
Stale PRs (no activity >7 days />14 days)
No stale PRs. The 1 open PR is fresh (opened 2026-03-23, updated 2026-03-24).
Unassigned Bugs
No open issues with the bug label.
Recommended Actions
- Review/merge #377:
ci(deps): update bfra-me/.github to v4.13.8(opened 2026-03-23, needs review) - Repository is healthy — 0 security alerts, CI green on main
Notes
- ★3 PRs merged since last run (2026-03-23):
- ★1 new PR opened: #377
ci(deps): update bfra-me/.github to v4.13.8 - Dependency Dashboard #2 updated today (2026-03-24T06:55Z)
- Main branch CI: Scorecard ✅ success (2026-03-24T08:02Z); CI ✅ success (2026-03-23T19:59Z)
2026-03-23 (UTC)
Summary Metrics
| Metric | Value |
|---|---|
| New issues (since last run) | 0 (★1 opened & closed: #348) |
| Open PRs | 2 (★2 new: #375, #374) |
| Stale issues (>30 days) | 0 |
| Stale PRs (>7 days) | 0 |
| Main branch checks | ✅ Scorecard: success (2026-03-23T05:17Z); ✅ Update Repo Settings: success (2026-03-23T05:17Z); Renovate: skipped |
| Security alerts (Dependabot) | ✅ 0 open — all resolved |
Stale Issues (no activity >30 days)
No stale issues. 2 open issues (#252 Daily Maintenance Report, #2 Dependency Dashboard).
Stale PRs (no activity >7 days />14 days)
No stale PRs. Both open PRs are fresh (opened today).
Unassigned Bugs
No open issues with the bug label.
Recommended Actions
- Review/merge 2 open PRs:
- Repository is healthy — 0 security alerts, CI green
Notes
- ★15 PRs merged since last run (2026-03-22–2026-03-23):
- #373:
build(deps): update dependency anomalyco/opencode to v1.3.0 - #372:
ci: reduce permissions on app-driven workflows - #371:
chore(release): pending release v0.31.2 - #370:
fix(release): overhaul release workflow architecture - #369:
ci(deps): update bfra-me/.github to v4.13.6 - #368, #366, #364:
chore(release): pending release v0.31.2(intermediate) - #367, #365, #363, #361, #359, #358, #357: release workflow fixes
- #373:
- Issue #348 (Dependabot Security Alerts - March 2026) opened and closed 2026-03-22
- ★Update Repo Settings workflow: now ✅ success after series of release fixes
- Dependency Dashboard #2 updated today (Renovate active)
- Latest commit:
717643b— "build(deps): update dependency anomalyco/opencode to v1.3.0"
2026-03-22 (UTC)
Summary Metrics
| Metric | Value |
|---|---|
| New issues (since last run) | 0 |
| Open PRs | 0 |
| Stale issues (>30 days) | 0 |
| Stale PRs (>7 days) | 0 |
| Main branch checks | ✅ CI: success (2026-03-21T19:29Z); ⏳ Fro Bot: in progress (this run) |
| Security alerts (Dependabot) | ✅ 0 open — all resolved |
Stale Issues (no activity >30 days)
No stale issues. 2 open issues (#252 Daily Maintenance Report, #2 Dependency Dashboard).
Stale PRs (no activity >7 days />14 days)
No open PRs.
Unassigned Bugs
No open issues with the bug label.
Recommended Actions
- Repository is healthy — 0 security alerts, CI green
Notes
- ★2 PRs merged since last run (2026-03-21):
- Dependency Dashboard #2 updated today
- 0 Dependabot security alerts — all resolved
2026-03-21 (UTC)
Summary Metrics
| Metric | Value |
|---|---|
| New issues (since last run) | 0 |
| Open PRs | 3 (★1 new: #346; 2 carried: #340, #339) |
| Stale issues (>30 days) | 0 |
| Stale PRs (>7 days) | 0 |
| Main branch checks | ⏳ Fro Bot: in progress (this run); Renovate: skipped; ★Update Repo Settings: failure (2026-03-21T04:50:02Z — new failure) |
| Security alerts (Dependabot) | Data unavailable via API (carried forward: #41 fast-xml-parser from 2026-03-18) |
Stale Issues (no activity >30 days)
No stale issues. 2 open issues (#252 Daily Maintenance Report, #2 Dependency Dashboard).
Stale PRs (no activity >7 days />14 days)
No stale PRs. All 3 open PRs are dependency updates created 2026-03-19–2026-03-21, all active within the last 2 days.
Unassigned Bugs
No open issues with the bug label.
Recommended Actions
- ★ Investigate Update Repo Settings workflow failure (2026-03-21T04:50:02Z — new failure after fix PRs merged)
- Verify Dependabot alert #41:
fast-xml-parser(high severity, day 3 — unresolved since 2026-03-18) - Review/merge carried PRs:
- ★ Review/merge new PR:
- #346:
build(deps): update dependency oh-my-openagent to v3.12.3(opened today)
- #346:
Notes
- ★7 PRs merged since last run:
- #342:
build(deps): update dependency oh-my-openagent to v3.12.0 - #341:
ci(deps): update github/codeql-action action to v4.34.1 - #345:
fix(settings): update action to v4.13.4 and restore bypass_pull_request_allowances - #344:
fix(settings): use literal branch name v0 instead of glob v? - #343:
fix(settings): drop bypass_pull_request_allowances entirely - #332:
build(dev): update dependency tsdown to v0.21.4 - #328:
chore(dev): update dependency lint-staged to v16.4.0
- #342:
- ★1 new PR opened today: #346
build(deps): update dependency oh-my-openagent to v3.12.3 - ★Update Repo Settings workflow failure (new after fix PRs merged): failure at 2026-03-21T04:50:02Z after chore(dev): update dependency lint-staged to v16.4.0 #328 merge
- Dependency Dashboard #2 updated today (Renovate active)
- Security alerts API returned 404 — Dependabot data unavailable from this context
Historical Summary
Runs archived: 30 prior runs (2026-02-24 through 2026-03-20).
Unresolved items carried forward:
- ★ 10 open Dependabot security alerts (as of 2026-03-28):
- #52:
handlebarsCRITICAL (CVE-2026-33937) - JavaScript Injection via AST Type Confusion - #53:
handlebarsHIGH (CVE-2026-33938) - JavaScript Injection via @partial-block tampering - #54:
handlebarsHIGH (CVE-2026-33939) - DoS via Malformed Decorator Syntax - #55:
handlebarsHIGH (CVE-2026-33940) - JavaScript Injection via Type Confusion (dynamic partial) - #56:
handlebarsHIGH (CVE-2026-33941) - JavaScript Injection in CLI Precompiler - #47:
handlebarsMEDIUM (CVE-2026-33916) - Prototype Pollution XSS - #48:
picomatchHIGH (CVE-2026-33671) - ReDoS via extglob quantifiers - #49:
picomatchMEDIUM (CVE-2026-33672) - Method Injection in POSIX Character Classes - #50:
brace-expansionMEDIUM (CVE-2026-33750) - Zero-step sequence DoS - #51:
brace-expansionMEDIUM (CVE-2026-33750) - Zero-step sequence DoS
- #52:
Previously resolved items:
- Issue #200 (Issue Triage Summary - February 2026) closed on 2026-03-06 ✅
- Dependabot security alerts: Previous alerts (9
minimatchReDoS + 1rollupArbitrary File Write) were fixed prior to 2026-03-03 ✅ - Dependabot alert #28 (
tarSymlink Path Traversal) — opened 2026-03-11, resolved by 2026-03-15 ✅ - Dependabot alerts #29–#39 (
undicivulnerabilities) — opened 2026-03-14, resolved by 2026-03-15 ✅ - Dependabot alert #41 (
fast-xml-parserhigh severity) — opened 2026-03-18, resolved by 2026-03-22 ✅ - Dependabot alerts #45, #46 (
picomatch) — opened 2026-03-27, resolved by 2026-03-28 ✅ - Update Repo Settings workflow failures (2026-03-19–2026-03-21) — resolved by 2026-03-23 ✅