security: fix CVE-2026-82533 Harness pin #15
No reviewers
Labels
No labels
accessibility
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
security
testing
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
nsaspy/agentProlog!15
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "security/cve-2026-82533-harness"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Fixes #13
Fixes #14
Security hardening for DeepSeek Harness CVE-2026-82533:
@deepseek-ai/dsh-*pins from vulnerable0.1.1-rc.2to fixed0.1.2-rc.1a66e4702047846cdaa10c66c9d3df3951f5ea70dharness_security_blockedpnpm-lock.yamland export it as an artifact; this workflow change will be reverted to frozen-lock mode after the generated lockfile is committedThe final PR will retain
pnpm install --frozen-lockfile.View command line instructions
Manual merge helper
Use this merge commit message when completing the merge manually.
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.