Upstream advisories on transitive leptos-stack crates (tracked, not directly fixable here):
paste (RUSTSEC-2024-0436, unmaintained) — pulled by leptos, tachys,
reactive_graph, reactive_stores, and either_of. No maintained
replacement exists in the pinned leptos 0.8 line; resolve by tracking the
upstream leptos migration off paste.
proc-macro-error2 (RUSTSEC-2026-0173, unmaintained) — pulled by
rstml → syn_derive. Same upstream-tracking resolution; there is no
reachable direct replacement through the leptos macro stack.
System dependencies
Tool
Version
License
Purpose
Docker Engine
≥24.0
Apache-2.0
Container runtime
Docker Compose
V2
Apache-2.0
Multi-container orchestration
Go
≥1.25
BSD-3-Clause
Build language for the cheasee-pi CLI
Node.js
≥22
MIT
JavaScript runtime
Python 3
≥3.10
PSF
Web scraping, search tools
ripgrep (rg)
latest
MIT
Fast code search
ast-grep
≥0.42
MIT
Structural code search
GitHub CLI (gh)
latest
MIT
GitHub API client
jscpd
4.2.4
MIT
Duplicate code detection
osv-scanner
v2.4.0
Apache-2.0
Vulnerability scanning (audit pipeline)
eslint
latest
MIT
JS/TS linting (extension checks)
pyright
latest
MIT
Python type checking
rust-analyzer
latest
MIT/Apache-2.0
Rust LSP server
gopls
latest
BSD-3-Clause
Go LSP server
typescript-language-server
latest
MIT
TypeScript LSP server
fd-find
latest
MIT/Apache-2.0
Fast file search (fd)
universal-ctags
latest
GPL-2.0
Code index for tag generation
jq
latest
MIT
JSON processor for shell scripts
unzip
latest
Info-ZIP
Archive extraction
git
—
GPL-2.0
Version control, worktrees
gosu
—
Apache-2.0
UID/GID mapping in container
Python packages (venv)
Package
License
Purpose
scrapling[fetchers]
MIT
Web crawling with progressive fetching
markdownify
MIT
HTML to Markdown conversion
beautifulsoup4
MIT
HTML parsing (scrapling dependency)
ddgs
MIT
DuckDuckGo search API
Playwright Chromium
Apache-2.0
Browser automation for web crawling
Pi extensions
Extension
Type
Purpose
structural-analyzer
Core tool
AST-aware code search via ast-grep
ripgrep-search
Core tool
Fast text/regex search via ripgrep
scrapling
Core tool
Web crawling with Cloudflare bypass
web-search
Core tool
DuckDuckGo search
supervisor
Pipeline
Kanban multi-agent orchestration
context-info
UX
Rich TUI status bar
session-logger
UX
Session logging to JSONL
agent-harness
Safety
Runtime tool call validation
caveman
Communication
Token-efficient protocol
ask-user
Interaction
Interactive MC/freetext questions + JSONL logging
format-on-save
DX
Auto Prettier + ESLint after write/edit
tsc-checkpoint
DX
TypeScript type checking
worktree-sandbox
Safety
Worktree path enforcement
rtk
Core tool
Token-saving bash rewrite via rtk binary (60-90% less output)
lsp-auditor
Pipeline
LSP diagnostics pre-audit
zzz-dump-context
Debug
System prompt capture + dump
Docker image base
Base image: Debian 12-slim (bookworm)
Image name:cheasee-pi
Build context:cmd/cheasee-pi/embedded/docker/Dockerfile (canonical source, embedded via //go:embed and extracted to a cache dir at runtime)