chore: maintenance updates - #244
Merged
Merged
Conversation
- Added 4 Docker CVE suppression(s) to .grype.yaml - Added 4 GHSA ID(s) to audit-ci.jsonc allowlist - Added 4 npm vulnerability ignore(s) to .grype.yaml - Confidence score: 100% 🤖 Generated with ml-repo-maintenance Co-Authored-By: ml-repo-maintenance <noreply@mojaloop.org>
gibaros
requested review from
bushjames,
elnyry-sam-k,
shashi165 and
vijayg10
as code owners
February 23, 2026 02:36
…audit-ci/grype - Removed minimatch 10.2.1 override (major version break) - Bumped fast-xml-parser 5.3.4 → 5.3.6 (fixes GHSA-m7jm/jmr7) - Removed fast-xml-parser GHSAs from audit-ci.jsonc and .grype.yaml - Added GHSA-3ppc-4f35-3m26 to audit-ci.jsonc (minimatch unfixable) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Regenerate package-lock.json to fix npm ci EUSAGE error caused by stale minimatch@10.2.1 and brace-expansion entries from removed overrides - Remove stale .grype.yaml entries referencing old 22.20.0-alpine3.22 base image (GHSA-5j98-mcp5-4vw2 glob, CVE-2025-46394/CVE-2024-58251 busybox, CVE-2025-56200 validator) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🔒 Security & Dependency Updates
Summary
This PR updates dependencies and applies security patches to address vulnerabilities.
Confidence Score: 100% ✅ (Standard PR - ready for review)
🐳 Docker Image Updates
Docker CVE Suppressions
Added 4 Docker-specific vulnerability suppression(s) to
.grype.yaml.These are Alpine (apk), Node.js binary, or base image npm vulnerabilities that cannot be fixed via application dependencies.
Docker Image Scan Results
📋 Audit CI Allowlist Updates
Added 4 unfixable vulnerability ID(s) to
audit-ci.jsoncallowlist.These are transitive vulnerabilities in upstream dependencies that cannot be resolved here.
🔍 Grype npm Vulnerability Ignores
Added 4 unfixable npm vulnerability ignore(s) to
.grype.yaml.These are transitive npm vulnerabilities that are also checked by Grype CI scans.
✅ Validation Results
No validation checks were run.
🤖 Automated Changes
This PR was automatically generated by ml-repo-maintenance.
Changed Files:
package.json- Updated dependency versions and added npm overrides.grype.yaml- Added Docker vulnerability suppressions and npm vulnerability ignoresReview Checklist:
🤖 Generated with ml-repo-maintenance
Co-Authored-By: ml-repo-maintenance noreply@mojaloop.org