Skip to content
This repository was archived by the owner on Sep 16, 2026. It is now read-only.

chore(CP-12104): patch critical and high library dependencies - #2

Open
tannerhelton wants to merge 1 commit into
mainfrom
feature/cp-12104-dependency-security
Open

tannerhelton wants to merge 1 commit into
mainfrom
feature/cp-12104-dependency-security

Conversation

@tannerhelton

Copy link
Copy Markdown
Member

Summary

Patch available dependency paths using scoped npm overrides for serialize-javascript, tar, tmp, and image-size 1.2.1.

Remaining findings: image-size 1.2.1 is still affected by GHSA-w3rx-r6r6-pgpr and GHSA-5p2g-fcmc-qvqq, with no published fixed version in the upstream advisories. The requested install-hook source patch was explicitly declined; these two findings are left open. This PR does not add an installation hook.

Scope

Update the dependency paths associated with the critical/high library findings returned by pup from the Datadog devops organization.

Out of scope

Deployment and release promotion.

Verification

  • npm install, TypeScript build and lint passed.
  • All 7 plugin tests passed.
  • Advisory range comparison: 19 Datadog finding rows cleared; the two image-size findings above remain.

The resolved lockfile was compared against the upstream advisory affected ranges for these Datadog findings. Datadog may continue to show the base-branch findings until this change is merged and rescanned.

UI evidence

No visual changes.

Related work

CP-12104 tracks the cross-repository remediation.

Co-authored-by: Codex <noreply@openai.com>
@tannerhelton
tannerhelton marked this pull request as ready for review September 3, 2026 23:33
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant