fix: Security updates - #48
StepSecurity Required Checks
Finished StepSecurity Required Checks
- NPM Compromised Packages Check - Checks for compromised npm package versions in the PR
- PyPI Compromised Packages Check - Checks for compromised PyPI package versions in the PR
- Pwn Request Vulnerabilities Check - Checks for Pwn Request vulnerabilities in the PR via risky triggers
- NPM Package Cooldown Check - Fails if any package version in the PR was released within the configured cooldown period, helping to avoid brand-new (and potentially unreviewed or malicious) releases
- PyPI Package Cooldown Check - Fails if any PyPI package version in the PR was released within the configured cooldown period
- Maven Compromised Packages Check - Checks for compromised Maven package versions in the PR
- Maven Package Cooldown Check - Fails if any Maven package version in the PR was released within the configured cooldown period
- Script Injection Check - Checks for script injection vulnerabilities in the PR
Details
✅ PyPI Package Cooldown Check
No PyPI package upgrades to recent releases found in current PR.
✅ Script Injection Vulnerabilities Check
No Script Injection vulnerabilities found in this PR.
✅ Pwn Request Vulnerabilities Check
No Pwn Request vulnerabilities found in this PR.
✅ Maven Package Cooldown Check
No Maven package upgrades to recent releases found in current PR.
✅ PyPI Compromised Packages Check
No compromised PyPI package versions found in current PR.
✅ Maven Compromised Packages Check
No compromised Maven package versions found in current PR.
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
✅ NPM Package Cooldown Check
No npm package upgrades to recent releases found in current PR.
The following npm packages are inspected in current PR (showing first 10 of 36 packages)
| Package Name | Previous Version | Current Version | file | Current Version Release Date |
|---|---|---|---|---|
| @preact/signals | 2.9.0 | 2.9.4 | package-lock.json | 2026-07-15T08:51:09Z |
| @nodable/entities | 2.1.0 | 3.0.0 | package-lock.json | 2026-07-14T02:22:09Z |
| dompurify | 3.4.11 | 3.4.12 | package-lock.json | 2026-07-11T12:11:29Z |
| fast-xml-builder | 1.2.0 | 1.3.0 | package-lock.json | 2026-07-11T12:02:42Z |
| is-unsafe | 2.0.0 | package-lock.json | 2026-07-11T09:26:23Z | |
| @floating-ui/utils | 0.2.11 | 0.2.12 | package-lock.json | 2026-07-11T08:41:33Z |
| @floating-ui/dom | 1.7.6 | 1.8.0 | package-lock.json | 2026-07-11T08:41:32Z |
| @floating-ui/core | 1.7.5 | 1.8.0 | package-lock.json | 2026-07-11T08:41:32Z |
| preact | 10.29.2 | 10.29.7 | package-lock.json | 2026-07-08T17:34:12Z |
| path-expression-matcher | 1.5.0 | 1.6.2 | package-lock.json | 2026-07-08T09:46:12Z |
⏲️ History
Previous invocation results of same check:
✅ Script Injection Vulnerabilities Check
No Script Injection vulnerabilities found in this PR.
✅ Maven Package Cooldown Check
No Maven package upgrades to recent releases found in current PR.
✅ Pwn Request Vulnerabilities Check
No Pwn Request vulnerabilities found in this PR.
✅ Maven Compromised Packages Check
No compromised Maven package versions found in current PR.
✅ PyPI Package Cooldown Check
No PyPI package upgrades to recent releases found in current PR.
✅ PyPI Compromised Packages Check
No compromised PyPI package versions found in current PR.
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
✅ NPM Package Cooldown Check
No npm package upgrades to recent releases found in current PR.