Skip to content

Patch compatible Timing Oracle tooling advisory ranges - #25

Merged
systemslibrarian merged 1 commit into
mainfrom
repair/timing-tooling-security-20261009
Oct 9, 2026
Merged

systemslibrarian merged 1 commit into
mainfrom
repair/timing-tooling-security-20261009

Conversation

@systemslibrarian

Copy link
Copy Markdown
Owner

Patch only compatible locked development-tooling versions: brace-expansion, compression, ip-address, js-yaml, body-parser and qs. The package manifest and application source are unchanged; source-map-js remains 1.2.2. This removes the observed patched advisory ranges without overriding or downgrading dependencies.

Validation on Node24: clean npm ci, unchanged lint, 42 unit tests, production build, all 16 browser/claims/accessibility tests, and separate root-base Lighthouse build pass. The existing quality/Lighthouse job, deployment needs and permissions are unchanged.

This is a partial security repair: current LHCI/publisher chains still contain unpatched or major-constrained sprintf-js, tmp, uuid, extract-zip, basic-ftp and braces. Their blockers remain explicit; npm audit is not claimed clean. No security finding was dismissed, and the historical unavailable Dependabot updater logs are separate. Final reviewed head 72d0c09.

@systemslibrarian
systemslibrarian merged commit 55e9bac into main Oct 9, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant