-
Notifications
You must be signed in to change notification settings - Fork 0
Reduce critical/high vulnerabilities from audit #83
Copy link
Copy link
Open
Labels
area:securitySecurity and dependency riskSecurity and dependency riskdependenciesPull requests that update a dependency filePull requests that update a dependency filepriority:highUrgent workUrgent workstatus:approvedApproved for implementationApproved for implementationstatus:needs-reviewNeeds maintainer reviewNeeds maintainer review
Milestone
Metadata
Metadata
Assignees
Labels
area:securitySecurity and dependency riskSecurity and dependency riskdependenciesPull requests that update a dependency filePull requests that update a dependency filepriority:highUrgent workUrgent workstatus:approvedApproved for implementationApproved for implementationstatus:needs-reviewNeeds maintainer reviewNeeds maintainer review
Context
pnpm audit --prod --audit-level highreports critical/high vulnerabilities in transitive dependencies.Problem
Current dependency graph includes vulnerable packages (examples:
simple-git,fast-xml-parser,handlebars,node-forge,vitepaths).Proposed Solution (Phased)
Wave A (low-risk)
Wave B (controlled upgrades)
Acceptance Criteria
pnpm lintandpnpm teststill passNotes
Apply small, reviewable commits to isolate breakages quickly.