fix(deps): clear Dependabot and full-audit vulnerabilities - #131
Open
Amir Bredy (ABMFST) wants to merge 8 commits into
Open
Amir Bredy (ABMFST) wants to merge 8 commits into
Amir Bredy (ABMFST) wants to merge 8 commits into
Conversation
Generate lockfile and version evidence on a read-only GitHub-hosted runner; no local npm execution. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 48993ee6-f068-4c4a-b317-2cd940fab804
Use public registry metadata from the hosted refresh, preserve optional platform entries, and guard every resolved xmldom copy against security regressions. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 48993ee6-f068-4c4a-b317-2cd940fab804
Stay on the supported Electron major and remove the unpatched extract-zip dependency through its upstream-maintained replacement. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 48993ee6-f068-4c4a-b317-2cd940fab804
Generate the patched dependency lockfile on a hosted runner and retain audit evidence. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Use a hosted Node 24 install to replace stale npm 10 workspace lock records and preserve native optional package metadata. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Cover the additional denial-of-service advisories reported by the complete hosted npm audit without changing dependency major versions. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Refresh overridden packages across all workspaces and assert security floors for brace-expansion, nanoid, xmldom and Electron installation tooling. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Record the clean npm 11 dependency graph and remove the temporary refresh workflow. Preserve cross-platform optional binaries and public-registry resolutions. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Validation
Flavor and release flow
Merge status
Required independent approving review is pending. The normal merge attempt was blocked by branch policy; no protection settings were changed.