fix(sec): suppress CVE-2026-33845, bump to v0.1.6, track CLAUDE.md#186
Merged
fix(sec): suppress CVE-2026-33845, bump to v0.1.6, track CLAUDE.md#186
Conversation
…loses #184) - Add CVE-2026-33845 (libgnutls30t64 GnuTLS DoS via DTLS zero-length fragment) to .trivyignore — no fixed version available in Debian 13; DTLS code path is unreachable in this PDF-processing application. Review date set to 2026-06-08. - Bump version to 0.1.6 across all three version files. - Remove CLAUDE.md from .gitignore and track it as project documentation; add explicit rule that all changes must go through a PR branch, never pushed directly to main.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pull Request
Summary
libgnutls30t64) in.trivyignore— no Debian 13 fix available; DTLS code path unreachable in this PDF-processing app. Review date 2026-06-08.CLAUDE.mdas project documentation (removes from.gitignore); adds explicit rule that all changes must go via a PR branch, never pushed directly tomain.Closes #184.
Changes
.trivyignore— CVE-2026-33845 suppressed with full justification and review dateCHANGELOG.md—[0.1.6]entry addedpackages/parser-core/pyproject.toml— 0.1.5 → 0.1.6packages/parser-core/src/bankstatements_core/__version__.py— 0.1.5 → 0.1.6packages/parser-free/pyproject.toml— 0.1.5 → 0.1.6.gitignore—CLAUDE.mdunignoredCLAUDE.md— tracked for the first time; "never push to main" rule addedType
Testing
Checklist
Downstream impact
bankstatements_core(exported class, function, or exception)