-
Notifications
You must be signed in to change notification settings - Fork 0
fix(deps): resolve 3 GitHub Dependabot vulnerabilities (2 high, 1 moderate) #13
Copy link
Copy link
Open
Description
Problem
GitHub push to CodeMonkeyCybersecurity/hera reported:
GitHub found 3 vulnerabilities on CodeMonkeyCybersecurity/hera's default branch (2 high, 1 moderate)
Action Required
- Review vulnerabilities at: https://github.com/CodeMonkeyCybersecurity/hera/security/dependabot
- Triage: determine if they are in
devDependenciesonly (lower risk) or in runtime code - Apply Dependabot-suggested updates
- Run
npm auditand resolve any remaining issues - Per SECURITY.md: Critical/High CVEs block merge, Medium require issue + remediation plan
Assessment
Current devDependencies in package.json:
@vitest/coverage-v8: ^4.0.7vitest: ^4.0.7eslint: ^8.57.0husky: ^9.1.7jsdom: ^27.1.0happy-dom: ^20.0.10
Runtime dependencies:
ae-cvss-calculator: ^1.0.0
The 2 HIGH CVEs should be treated as P1 (fix this week) per governance TESTING.md §Coverage Thresholds.
Priority: P1 if in runtime deps, P2 if devDependencies only (verify first)
Refs: Discovered during push in fix/1-auth-issue-database-runtime-crashes
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels