Skip to content

chore: refresh Action dependency security fixes - #9

Merged
attomus-gh merged 1 commit into
mainfrom
chore/action-audit-refresh-2026-08-05
Aug 5, 2026
Merged

chore: refresh Action dependency security fixes#9
attomus-gh merged 1 commit into
mainfrom
chore/action-audit-refresh-2026-08-05

Conversation

@attomus-gh

Copy link
Copy Markdown
Contributor

Summary

  • refresh vulnerable transitive dependency resolutions
  • rebuild the committed Action bundle against the patched runtime graph
  • restore the high-severity npm audit gate to green

Security fixes

  • brace-expansion 5.0.9
  • fast-uri 3.1.5
  • nanoid 3.3.17
  • postcss 8.5.25
  • undici 6.28.0

Verification

  • npm run verify
  • npm audit --audit-level=high: 0 vulnerabilities
  • gitleaks detect --no-banner -v --redact: no leaks
  • git diff --check

Release gate

This is a dependency-only hardening pass against main. It changes no Action inputs, server contracts, or shared-harness behavior.

@attomus-gh
attomus-gh marked this pull request as ready for review August 5, 2026 12:45
@attomus-gh
attomus-gh merged commit c2d5496 into main Aug 5, 2026
1 check passed
@attomus-gh
attomus-gh deleted the chore/action-audit-refresh-2026-08-05 branch August 5, 2026 12:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant