Skip to content

fix(security): correct false npm-audit claim + SHA-pin Trivy + gate HIGH#31

Merged
heznpc merged 2 commits into
mainfrom
fix/wave5a-mechanical
Jun 3, 2026
Merged

fix(security): correct false npm-audit claim + SHA-pin Trivy + gate HIGH#31
heznpc merged 2 commits into
mainfrom
fix/wave5a-mechanical

Conversation

@heznpc

@heznpc heznpc commented Jun 3, 2026

Copy link
Copy Markdown
Member

No description provided.

@heznpc heznpc enabled auto-merge (squash) June 3, 2026 22:14
…mage CVEs)

Self-correction: the prior commit raised Trivy to CRITICAL,HIGH, which turned
CI red on CVE-2026-33671 (picomatch ReDoS, HIGH, fixed) bundled in the node:22
image's own npm — a base-image CVE the template can't remediate. Revert the
gate to CRITICAL (the deliberate original setting), fix the rationale comment
to not reference the nonexistent npm-audit step, and align the docs
(SECURITY.md, README) to CRITICAL. The Trivy SHA-pin and the removal of the
false 'npm audit on every push' claim are kept.
@heznpc heznpc merged commit 0f7bac8 into main Jun 3, 2026
4 checks passed
@heznpc heznpc deleted the fix/wave5a-mechanical branch June 3, 2026 22:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant