Skip to content

chore: maintenance updates - #244

Merged
gibaros merged 4 commits into
mainfrom
chore/deps-security-20260223
Feb 25, 2026
Merged

gibaros merged 4 commits into
mainfrom
chore/deps-security-20260223

Conversation

@gibaros

@gibaros gibaros commented Feb 23, 2026

Copy link
Copy Markdown
Contributor

🔒 Security & Dependency Updates


Summary

This PR updates dependencies and applies security patches to address vulnerabilities.

Confidence Score: 100% ✅ (Standard PR - ready for review)


🐳 Docker Image Updates

Docker CVE Suppressions

Added 4 Docker-specific vulnerability suppression(s) to .grype.yaml.
These are Alpine (apk), Node.js binary, or base image npm vulnerabilities that cannot be fixed via application dependencies.

Docker Image Scan Results

Category Count
npm (application) 0
npm (base image) 15
Alpine (apk) 4
Binary (Node.js) 0
Total 19

📋 Audit CI Allowlist Updates

Added 4 unfixable vulnerability ID(s) to audit-ci.jsonc allowlist.
These are transitive vulnerabilities in upstream dependencies that cannot be resolved here.

GHSA ID
GHSA-m7jm-9gc2-mpf2
GHSA-87r5-mp6g-5w5j
GHSA-jmr7-xgp7-cmfj
GHSA-2g4f-4pwh-qvx6

🔍 Grype npm Vulnerability Ignores

Added 4 unfixable npm vulnerability ignore(s) to .grype.yaml.
These are transitive npm vulnerabilities that are also checked by Grype CI scans.

GHSA/CVE ID Package
GHSA-m7jm-9gc2-mpf2 fast-xml-parser
GHSA-87r5-mp6g-5w5j jsonpath
GHSA-jmr7-xgp7-cmfj fast-xml-parser
GHSA-2g4f-4pwh-qvx6 unknown

✅ Validation Results

No validation checks were run.


🤖 Automated Changes

This PR was automatically generated by ml-repo-maintenance.

Changed Files:

  • package.json - Updated dependency versions and added npm overrides
  • .grype.yaml - Added Docker vulnerability suppressions and npm vulnerability ignores

Review Checklist:

  • Review dependency updates for breaking changes
  • Review security patches
  • Check test coverage
  • Verify build artifacts

🤖 Generated with ml-repo-maintenance

Co-Authored-By: ml-repo-maintenance noreply@mojaloop.org

- Added 4 Docker CVE suppression(s) to .grype.yaml
- Added 4 GHSA ID(s) to audit-ci.jsonc allowlist
- Added 4 npm vulnerability ignore(s) to .grype.yaml
- Confidence score: 100%

🤖 Generated with ml-repo-maintenance

Co-Authored-By: ml-repo-maintenance <noreply@mojaloop.org>
gibaros and others added 3 commits February 23, 2026 00:51
…audit-ci/grype

- Removed minimatch 10.2.1 override (major version break)
- Bumped fast-xml-parser 5.3.4 → 5.3.6 (fixes GHSA-m7jm/jmr7)
- Removed fast-xml-parser GHSAs from audit-ci.jsonc and .grype.yaml
- Added GHSA-3ppc-4f35-3m26 to audit-ci.jsonc (minimatch unfixable)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Regenerate package-lock.json to fix npm ci EUSAGE error caused by
  stale minimatch@10.2.1 and brace-expansion entries from removed overrides
- Remove stale .grype.yaml entries referencing old 22.20.0-alpine3.22
  base image (GHSA-5j98-mcp5-4vw2 glob, CVE-2025-46394/CVE-2024-58251
  busybox, CVE-2025-56200 validator)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@elnyry-sam-k elnyry-sam-k left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@gibaros
gibaros merged commit d0b78a4 into main Feb 25, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants