Skip to content

Address security and quality audit findings#90

Merged
b-per merged 1 commit intomainfrom
fix/security-audit-remediation
Mar 13, 2026
Merged

Address security and quality audit findings#90
b-per merged 1 commit intomainfrom
fix/security-audit-remediation

Conversation

@b-per
Copy link
Contributor

@b-per b-per commented Mar 13, 2026

Summary

  • W007 (Snyk): Replace literal token placeholders with ${ENV_VAR} references in configuring-dbt-mcp-server templates; add credential warning for .mcp.json version control
  • W011 (Snyk): Strengthen untrusted-content boundaries with explicit URL/source callouts in using-dbt-for-analytics-engineering, troubleshooting-dbt-job-errors, and migrating-dbt-core-to-fusion
  • W012 (Snyk): Add first-party provenance notes for dbt-autofix and dbt Fusion
  • Tessl quality: Consolidate overlapping "Important Notes" + "Anti-Patterns" sections and deduplicate repro command references in migrating-dbt-core-to-fusion
  • Bump plugin versions: dbt 1.1.2, dbt-migration 1.1.1, tile 1.1.1

- W007: Replace literal token placeholders with env var references in configuring-dbt-mcp-server templates
- W011: Strengthen untrusted-content boundaries with explicit URL/source callouts across 3 skills
- W012: Add first-party provenance notes for dbt-autofix and dbt Fusion
- Tessl: Consolidate overlapping sections in migrating-dbt-core-to-fusion
- Bump plugin versions (dbt 1.1.2, dbt-migration 1.1.1, tile 1.1.1)
@b-per b-per requested a review from a team as a code owner March 13, 2026 11:37
@b-per
Copy link
Contributor Author

b-per commented Mar 13, 2026

Simply minor updates to improve the status reported by automated code scanning tools

@b-per b-per merged commit faadc25 into main Mar 13, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant