Skip to content

fix: resolve osv-scanner High/Medium advisories via patch-level lockfile bumps - #156

Merged
zircote merged 1 commit into
mainfrom
fix/osv-lockfile-advisories
Aug 10, 2026
Merged

fix: resolve osv-scanner High/Medium advisories via patch-level lockfile bumps#156
zircote merged 1 commit into
mainfrom
fix/osv-lockfile-advisories

Conversation

@zircote

@zircote zircote commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

sca / osv-scanner has failed on main and every PR since these advisories published — currently blocking auto-merge of the catalog re-pin #155 (mif-docs v0.9.6). Same fix shape as mif-docs-plugin#226: bump each package within its existing semver range, lockfile-only, no manifest changes.

Resolves all 8 findings (2 High, 5 Medium, 1 Low). astro build passes locally. Supersedes Dependabot #153 and #154.

…ile bumps

sca / osv-scanner has failed on main and every PR since the advisories
published, which also blocks the automerge of catalog re-pin PRs (#155
sat BLOCKED on it). Bump each package within its existing semver range:
dompurify 3.4.12 -> 3.4.13 (GHSA-55q2-fjhq-7xh7), js-yaml 4.3.0 -> 4.3.1
(GHSA-5p4m-2wfm-xmqj), nanoid 3.3.16 -> 3.3.18 (GHSA-2v37-7h3g-55p8),
mermaid 11.16.0 -> 11.16.1 (5 advisories). Lockfile-only, no manifest
changes; astro build passes. Supersedes Dependabot #153/#154.
Copilot AI lite review requested due to automatic review settings August 10, 2026 17:39

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@zircote
zircote merged commit c6a3515 into main Aug 10, 2026
23 checks passed
@zircote
zircote deleted the fix/osv-lockfile-advisories branch August 10, 2026 17:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants