plano/.github/workflows
Adil Hafeez 1df43872a6
Fix code scanning and dependabot security alerts (#756)
* Fix code scanning and dependabot security alerts

Code scanning fixes (14 alerts):
- Fix XSS in OG image route by validating request origin against allowlist
- Fix incomplete URL sanitization in blog layout using exact hostname matching
- Bind port-check socket to 127.0.0.1 instead of 0.0.0.0
- Add explicit permissions to 7 GitHub Actions workflows

Dependabot fixes:
- Update @isaacs/brace-expansion 5.0.0 -> 5.0.1 (CVE-2026-25547)
- Update bytes 1.10.1 -> 1.11.1 (CVE-2026-25541)
- Update time 0.3.41 -> 0.3.47 (CVE-2026-25727)
- Update cryptography 45.0.7 -> 46.0.5 (CVE-2026-26007)
- Update python-multipart 0.0.20 -> 0.0.22 (CVE-2026-24486)
- Update urllib3 2.6.2 -> 2.6.3 in test lockfiles (CVE-2026-21441)
- Update Werkzeug 3.1.4 -> 3.1.5 (CVE-2026-21860)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Address PR review feedback

- Replace plano.katanemo.com with planoai.dev in allowed hosts
- Add planoai.dev to OG route and blog layout allowlists
- Revert socket bind to 0.0.0.0 (intentional for port-in-use check)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-14 12:27:07 -08:00
..
docker-push-main.yml Fix code scanning and dependabot security alerts (#756) 2026-02-14 12:27:07 -08:00
docker-push-release.yml Fix code scanning and dependabot security alerts (#756) 2026-02-14 12:27:07 -08:00
docker-security-scan.yml Add Trivy Docker security scan to CI (#755) 2026-02-13 19:53:49 -08:00
e2e_plano_tests.yml Fix code scanning and dependabot security alerts (#756) 2026-02-14 12:27:07 -08:00
e2e_test_currency_convert.yml Rename all arch references to plano (#745) 2026-02-13 15:16:56 -08:00
e2e_test_preference_based_routing.yml Rename all arch references to plano (#745) 2026-02-13 15:16:56 -08:00
e2e_tests.yml improve e2e tests (#731) 2026-02-09 13:20:06 -08:00
ghrc-push-main.yml restructure cli (#656) 2025-12-25 14:55:29 -08:00
ghrc-push-release.yml restructure cli (#656) 2025-12-25 14:55:29 -08:00
plano_tools_tests.yml use uv instead of poetry (#663) 2025-12-26 11:21:42 -08:00
pre-commit.yml Fix code scanning and dependabot security alerts (#756) 2026-02-14 12:27:07 -08:00
publish-pypi.yml use uv to publish planoai to pypi (#665) 2025-12-28 14:14:27 -08:00
rust_tests.yml Fix code scanning and dependabot security alerts (#756) 2026-02-14 12:27:07 -08:00
static.yml Fix code scanning and dependabot security alerts (#756) 2026-02-14 12:27:07 -08:00
validate_plano_config.yml Fix code scanning and dependabot security alerts (#756) 2026-02-14 12:27:07 -08:00