Skip to content

fix(deps): clear vulnerabilities in task dependencies - #22

Merged
tembleking merged 3 commits into
mainfrom
fix/deps-vulns
Oct 7, 2026
Merged

tembleking merged 3 commits into
mainfrom
fix/deps-vulns

Conversation

@tembleking

@tembleking tembleking commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Summary

Fixes 14 vulnerabilities (10 HIGH, 4 MEDIUM) in the transitive dependencies of package-lock.json and sysdig-cli-scan-task/package-lock.json. It also brings in the routine updates from just update.

Changes

fix(deps)

The task only uses core task-lib APIs (getInput, getBoolInput, getVariable, setVariable, setResult, tool, which, loc), and it compiles cleanly with tsc.

chore

  • nix flake update (nixpkgs 2026-06-16 → 2026-10-05)
  • tfx-cli 0.23.3 → 0.24.2
  • Updated pinned GitHub Actions: actions/checkout v7.0.1, nix-installer-action v23, magic-nix-cache-action v15, azure/login v3.1.0

Verification

  • adm-zip and uuid are no longer in the dependency tree, and brace-expansion resolves to 1.1.21
  • tsc build OK

Known remaining

  • braces@3.0.3 (GHSA-vfj7-8cjw-p6xm), via shelljs → fast-glob → micromatch. No fixed version has been published yet, so it is out of scope for now. The npm audit fix --force that npm suggests would downgrade task-lib, so I didn't apply it.

Release

Bumps version to 1.0.5 (package.json, task.json, vss-extension.json), so merging this publishes the extension to the Marketplace and tags 1.0.5.

@tembleking
tembleking enabled auto-merge (squash) October 7, 2026 13:10
@tembleking
tembleking merged commit 1208b2f into main Oct 7, 2026
6 checks passed
@tembleking
tembleking deleted the fix/deps-vulns branch October 7, 2026 13:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants