Finding · openhands
Security: Fix CVE-2026-42305 via dulwich upgrade to 1.2.5
What Changed
Updated dulwich library to version 1.2.5 to address CVE-2026-42305 security vulnerability affecting git operations.
Operator Implication
Operators must deploy this security patch to mitigate CVE-2026-42305 exposure in git operations library. Git-based workflows may be affected if vulnerability is exploitable.
Receipt
Finding metadata
Run: 2026-06-03-weekly-digest-2026-05-28_2026-06-03-frontier-v0
Finding ID: 2026-06-03-openhands-cve-2026-42305-dulwich
Accepted signals
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact