upgrade go deps, migrate cache to fido#17
Conversation
Kusari Analysis Results:Caution Flagged Issues Detected While code analysis shows no security vulnerabilities, the dependency analysis identifies two critical blockers that must be addressed: (1) GPL-3.0 licensing in github.com/codeGROOVE-dev/turnclient poses legal/compliance risk requiring derivative works to use the same copyleft license, potentially conflicting with your project's licensing model. (2) Newly added transitive dependency github.com/puzpuzpuz/xsync/v4 is unmaintained (0/10 score, no activity in 90 days), creating supply chain security risk as it won't receive security patches if vulnerabilities emerge. Action required: Verify GPL-3.0 compatibility with your project license or find alternative to turnclient with permissive licensing and actively maintained dependencies. The code itself is clean with no vulnerabilities, secrets, or security issues detected. Note View full detailed analysis result for more information on the output and the checks that were run. Required Dependency Mitigations
Found this helpful? Give it a 👍 or 👎 reaction! |
|
Kusari PR Analysis rerun based on - da7e920 performed at: 2026-01-17T16:32:12Z - link to updated analysis |
No description provided.