fix(deps): update build-tools and fix npm vulnerabilities#342
Open
platex-rehor-bot wants to merge 1 commit into
Open
fix(deps): update build-tools and fix npm vulnerabilities#342platex-rehor-bot wants to merge 1 commit into
platex-rehor-bot wants to merge 1 commit into
Conversation
RHCLOUD-48034 Update insights-frontend-builder-common submodule from a646e7b to 72c2bef: - Node UBI image 9.7 → 9.8 (fixes RPM CVEs: libarchive, libnghttp2, libcap) - caddy-ubi:latest floating tag pulls latest Go patches on rebuild - Go toolset updated to 1.25.9 (fixes stdlib CVEs) Run npm audit fix to resolve 13 non-breaking JS dependency vulnerabilities. Remaining 32 vulnerabilities require semver-major bumps (out of scope). Supersedes Mintmaker PRs RedHatInsights#339 and RedHatInsights#341 (targeted older a96ba3d). Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Update build-tools submodule and run npm audit fix to address vulnerability scan findings (33 total — 2 Critical, 16 High, 13 Medium, 2 Low).
Build-tools submodule update (a646e7b → 72c2bef):
npm audit fix: Resolved 13 non-breaking JS dependency vulnerabilities. Remaining 32 require semver-major bumps (out of scope for this ticket).
Supersedes Mintmaker PRs #339 and #341 (targeted older a96ba3d commit).
RHCLOUD-48034
Screenshots
N/A — infrastructure/dependency change only, no UI impact.
Checklist ☑️