Skip to content

security: revisit optional DiskCache advisory by 2026-10-31 #15

Description

@jason-allen-oneal

Dependabot alert #7 (GHSA-w8v5-vhqr-4h9v / CVE-2025-69872) has no patched DiskCache release.

Current risk boundary:

  • dependency exists only through the optional embed extra via llama-cpp-python
  • frozen default/runtime image excludes both llama-cpp-python and DiskCache
  • SignalGate does not enable llama-cpp DiskCache or expose a cache-directory sink
  • remediation evidence is recorded in PR fix: remediate dependency and supply-chain alerts #14

Reopen the alert before enabling that cache path, changing embed packaging, or when a patched release ships. Review this disposition no later than 2026-10-31.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions