Skip to content

fix(*): remediate dependency and code scanning vulnerabilities - #18

Merged
omermorad merged 7 commits into
nextfrom
fix/security-dependencies
Sep 29, 2026
Merged

omermorad merged 7 commits into
nextfrom
fix/security-dependencies

Conversation

@omermorad

@omermorad omermorad commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Configure weekly grouped Dependabot updates for npm and GitHub Actions on the default branch, next; keep security grouping enabled.
  • Upgrade vulnerable dependencies and apply targeted transitive overrides. pnpm audit reports no known vulnerabilities.
  • Further harden the release-preview, E2E simulation, and coverage workflows; add scheduled/PR dependency audits.
  • Preserve all security fixes and regression tests from merged fix(*): address security findings on next #19 and the workflow changes from merged fix(*): prepare next workflow and release safeguards #17, including Node 22/24/26 CI.
  • Secret scanning and push protection are enabled. Secret alert fix: build step should not contain watch #1 remains open because revocation has not been confirmed. No alert has been dismissed to hide a finding.
  • Rulesets are managed directly in GitHub. No checked-in ruleset JSON, helper scripts, or custom package-verification action.

Conflict resolution

Merged latest next (361ad40) into this branch without force-pushing. Resolved the release-preview.yml conflict by retaining the simplified hardened preview and its next-only checkout, read-only permissions, and disabled credential persistence. #17 and #19 are already merged; the remaining diff contains the dependency and additional workflow hardening.

Validation after merging next

  • Build and lint: passed.
  • Unit tests: 8 passed.
  • E2E tests: 339 passed, 1 skipped, including all 16 Advanced Security regressions.
  • pnpm audit --audit-level low: no known vulnerabilities.
  • GitHub CI reruns after this push. Alerts close only after fixes merge and scans update; secret revocation requires the owner.

No package versions, tags, npm distribution tags, or GitHub Releases were published or changed.

@omermorad
omermorad merged commit ee6d9a3 into next Sep 29, 2026
10 checks passed
@omermorad
omermorad deleted the fix/security-dependencies branch September 29, 2026 06:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant