Skip to content

feat: production-ready platform — lakehouse, ML/DL/GNN, simulation engines, middleware integration#19

Merged
munisp merged 90 commits into
mainfrom
devin/1777666970-production-ready
Jun 16, 2026
Merged

feat: production-ready platform — lakehouse, ML/DL/GNN, simulation engines, middleware integration#19
munisp merged 90 commits into
mainfrom
devin/1777666970-production-ready

feat: wire middleware events, Permify enforcement, and API versioning

fc4d055
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / Trivy failed Jun 7, 2026 in 3s

32 new alerts including 2 critical severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 2 critical
  • 13 high
  • 11 medium
  • 6 low

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check failure on line 2379 in workers/rust/Cargo.lock

See this annotation in the file changed.

Code scanning / Trivy

rustls-webpki: Denial of service via panic on malformed CRL BIT STRING High

Package: rustls-webpki
Installed Version: 0.103.9
Vulnerability GHSA-82j2-j2ch-gfr8
Severity: HIGH
Fixed Version: 0.103.13, 0.104.0-alpha.7
Link: GHSA-82j2-j2ch-gfr8

Check failure on line 1718 in workers/rust/Cargo.lock

See this annotation in the file changed.

Code scanning / Trivy

rust-openssl: rust-openssl: Arbitrary code execution via specially crafted certificate High

Package: openssl
Installed Version: 0.10.75
Vulnerability CVE-2026-42327
Severity: HIGH
Fixed Version: 0.10.79
Link: CVE-2026-42327

Check failure on line 1718 in workers/rust/Cargo.lock

See this annotation in the file changed.

Code scanning / Trivy

rust-openssl provides OpenSSL bindings for the Rust programming langua ... High

Package: openssl
Installed Version: 0.10.75
Vulnerability CVE-2026-41898
Severity: HIGH
Fixed Version: 0.10.78
Link: CVE-2026-41898

Check failure on line 1718 in workers/rust/Cargo.lock

See this annotation in the file changed.

Code scanning / Trivy

rust-openssl provides OpenSSL bindings for the Rust programming langua ... High

Package: openssl
Installed Version: 0.10.75
Vulnerability CVE-2026-41681
Severity: HIGH
Fixed Version: 0.10.78
Link: CVE-2026-41681

Check failure on line 1718 in workers/rust/Cargo.lock

See this annotation in the file changed.

Code scanning / Trivy

rust-openssl provides OpenSSL bindings for the Rust programming langua ... High

Package: openssl
Installed Version: 0.10.75
Vulnerability CVE-2026-41678
Severity: HIGH
Fixed Version: 0.10.78
Link: CVE-2026-41678

Check failure on line 1718 in workers/rust/Cargo.lock

See this annotation in the file changed.

Code scanning / Trivy

rust-openssl provides OpenSSL bindings for the Rust programming langua ... High

Package: openssl
Installed Version: 0.10.75
Vulnerability CVE-2026-41676
Severity: HIGH
Fixed Version: 0.10.78
Link: CVE-2026-41676

Check failure on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

tmp is a temporary file and directory creator for node.js. Prior to 0. ... High

Package: tmp
Installed Version: 0.2.5
Vulnerability CVE-2026-44705
Severity: HIGH
Fixed Version: 0.2.6
Link: CVE-2026-44705

Check failure on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality High

Package: uuid
Installed Version: 8.3.2
Vulnerability CVE-2026-41907
Severity: MEDIUM
Fixed Version: 11.1.1, 12.0.1, 13.0.1
Link: CVE-2026-41907

Check failure on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality High

Package: uuid
Installed Version: 10.0.0
Vulnerability CVE-2026-41907
Severity: MEDIUM
Fixed Version: 11.1.1, 12.0.1, 13.0.1
Link: CVE-2026-41907

Check failure on line 1 in orchestration/go/go.mod

See this annotation in the file changed.

Code scanning / Trivy

google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation Critical

Package: google.golang.org/grpc
Installed Version: v1.62.1
Vulnerability CVE-2026-33186
Severity: CRITICAL
Fixed Version: 1.79.3
Link: CVE-2026-33186

Check failure on line 26 in certs/ndsep-signing.key

See this annotation in the file changed.

Code scanning / Trivy

Asymmetric Private Key High

Artifact: certs/ndsep-signing.key
Type:
Secret Asymmetric Private Key
Severity: HIGH
Match: *****************************************************************

Check failure on line 27 in infra/nginx/ssl/privkey.pem

See this annotation in the file changed.

Code scanning / Trivy

Asymmetric Private Key High

Artifact: infra/nginx/ssl/privkey.pem
Type:
Secret Asymmetric Private Key
Severity: HIGH
Match: ****************************************************************

Check failure on line 1 in orchestration/go/go.mod

See this annotation in the file changed.

Code scanning / Trivy

golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing High

Package: github.com/golang-jwt/jwt/v5
Installed Version: v5.0.0
Vulnerability CVE-2025-30204
Severity: HIGH
Fixed Version: 5.2.2
Link: CVE-2025-30204

Check failure on line 1 in orchestration/go/go.mod

See this annotation in the file changed.

Code scanning / Trivy

golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto Critical

Package: golang.org/x/crypto
Installed Version: v0.21.0
Vulnerability CVE-2024-45337
Severity: CRITICAL
Fixed Version: 0.31.0
Link: CVE-2024-45337

Check failure on line 1 in orchestration/go/go.mod

See this annotation in the file changed.

Code scanning / Trivy

golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh High

Package: golang.org/x/crypto
Installed Version: v0.21.0
Vulnerability CVE-2025-22869
Severity: HIGH
Fixed Version: 0.35.0
Link: CVE-2025-22869

Check warning on line 1 in orchestration/go/go.mod

See this annotation in the file changed.

Code scanning / Trivy

golang.org/x/net/html: Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net Medium

Package: golang.org/x/net
Installed Version: v0.22.0
Vulnerability CVE-2025-22872
Severity: MEDIUM
Fixed Version: 0.38.0
Link: CVE-2025-22872

Check warning on line 2379 in workers/rust/Cargo.lock

See this annotation in the file changed.

Code scanning / Trivy

webpki: CRLs not considered authoritative by Distribution Point due to faulty matching logic Medium

Package: rustls-webpki
Installed Version: 0.103.9
Vulnerability GHSA-pwjx-qhcg-rvj4
Severity: MEDIUM
Fixed Version: 0.103.10, 0.104.0-alpha.5
Link: GHSA-pwjx-qhcg-rvj4

Check warning on line 2052 in workers/rust/Cargo.lock

See this annotation in the file changed.

Code scanning / Trivy

protobuf: Protobuf: Uncontrolled Recursion Vulnerability Medium

Package: protobuf
Installed Version: 2.28.0
Vulnerability CVE-2025-53605
Severity: MEDIUM
Fixed Version: 3.7.2
Link: CVE-2025-53605

Check warning on line 1718 in workers/rust/Cargo.lock

See this annotation in the file changed.

Code scanning / Trivy

rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers Medium

Package: openssl
Installed Version: 0.10.75
Vulnerability CVE-2026-45784
Severity: MEDIUM
Fixed Version: 0.10.80
Link: CVE-2026-45784

Check warning on line 1718 in workers/rust/Cargo.lock

See this annotation in the file changed.

Code scanning / Trivy

rust-openssl provides OpenSSL bindings for the Rust programming langua ... Medium

Package: openssl
Installed Version: 0.10.75
Vulnerability CVE-2026-44662
Severity: MEDIUM
Fixed Version: 0.10.79
Link: CVE-2026-44662

Check warning on line 1 in orchestration/go/go.mod

See this annotation in the file changed.

Code scanning / Trivy

golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net Medium

Package: golang.org/x/net
Installed Version: v0.22.0
Vulnerability CVE-2025-22870
Severity: MEDIUM
Fixed Version: 0.36.0
Link: CVE-2025-22870

Check warning on line 1 in orchestration/go/go.mod

See this annotation in the file changed.

Code scanning / Trivy

golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS Medium

Package: golang.org/x/net
Installed Version: v0.22.0
Vulnerability CVE-2023-45288
Severity: MEDIUM
Fixed Version: 0.23.0
Link: CVE-2023-45288

Check warning on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

### Summary `qs.stringify` throws `TypeError` when called with `arr ... Medium

Package: qs
Installed Version: 6.14.2
Vulnerability CVE-2026-8723
Severity: MEDIUM
Fixed Version: 6.15.2
Link: CVE-2026-8723

Check warning on line 1 in orchestration/go/go.mod

See this annotation in the file changed.

Code scanning / Trivy

golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication Medium

Package: golang.org/x/crypto
Installed Version: v0.21.0
Vulnerability CVE-2025-58181
Severity: MEDIUM
Fixed Version: 0.45.0
Link: CVE-2025-58181

Check warning on line 1 in orchestration/go/go.mod

See this annotation in the file changed.

Code scanning / Trivy

golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages Medium

Package: golang.org/x/crypto
Installed Version: v0.21.0
Vulnerability CVE-2025-47914
Severity: MEDIUM
Fixed Version: 0.45.0
Link: CVE-2025-47914