Skip to content

chore(deps): security fixes and toolchain updates [EXP-406]#99

Open
harshalpatel91 wants to merge 1 commit intomasterfrom
EXP-406
Open

chore(deps): security fixes and toolchain updates [EXP-406]#99
harshalpatel91 wants to merge 1 commit intomasterfrom
EXP-406

Conversation

@harshalpatel91
Copy link
Copy Markdown

  • Pin lodash 4.18.1; npm overrides for omit-deep-lodash, form-data, @tootallnate/once transitive issues
  • Upgrade esbuild beyond GHSA advisory range; bump uuid to ^11.x
  • Move Jest to 29 with jest-environment-jsdom; ts-jest and jsdom updates
  • Add jest.setup.js for TextEncoder/TextDecoder under jsdom
  • Set skipLibCheck in tsconfig for stable declaration builds

- Pin lodash 4.18.1; npm overrides for omit-deep-lodash, form-data,
  @tootallnate/once transitive issues
- Upgrade esbuild beyond GHSA advisory range; bump uuid to ^11.x
- Move Jest to 29 with jest-environment-jsdom; ts-jest and jsdom updates
- Add jest.setup.js for TextEncoder/TextDecoder under jsdom
- Set skipLibCheck in tsconfig for stable declaration builds

Co-authored-by: Cursor <cursoragent@cursor.com>
@harshalpatel91 harshalpatel91 requested a review from a team as a code owner May 6, 2026 14:00
@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 6, 2026

🔒 Security Scan Results

ℹ️ Note: Only vulnerabilities with available fixes (upgrades or patches) are counted toward thresholds.

Check Type Count (with fixes) Without fixes Threshold Result
🔴 Critical Severity 0 0 10 ✅ Passed
🟠 High Severity 0 0 25 ✅ Passed
🟡 Medium Severity 0 0 500 ✅ Passed
🔵 Low Severity 0 0 1000 ✅ Passed

⏱️ SLA Breach Summary

✅ No SLA breaches detected. All vulnerabilities are within acceptable time thresholds.

Severity Breaches (with fixes) Breaches (no fixes) SLA Threshold (with/no fixes) Status
🔴 Critical 0 0 15 / 30 days ✅ Passed
🟠 High 0 0 30 / 120 days ✅ Passed
🟡 Medium 0 0 90 / 365 days ✅ Passed
🔵 Low 0 0 180 / 365 days ✅ Passed

✅ BUILD PASSED - All security checks passed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant