Skip to content

Fix security scanning configuration - #8

Merged
mbtools merged 1 commit into
mainfrom
codex/security-scanning-fixes
Aug 14, 2026
Merged

Fix security scanning configuration#8
mbtools merged 1 commit into
mainfrom
codex/security-scanning-fixes

Conversation

@mbtools

@mbtools mbtools commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Pin the transitive immutable dependency to patched version 5.1.9.
  • Restrict the docs workflow token to read-only repository contents.
  • Add a harmless JavaScript source unit for the JavaScript/TypeScript CodeQL scan.

Validation

  • npm run docs:build
  • npm audit --omit=dev --json (zero production vulnerabilities)
  • git diff --check

@mbtools
mbtools marked this pull request as ready for review August 14, 2026 23:06
@mbtools
mbtools merged commit 9189815 into main Aug 14, 2026
5 checks passed
@mbtools
mbtools deleted the codex/security-scanning-fixes branch August 14, 2026 23:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant