Skip to content

Conversation

philvarner
Copy link
Collaborator

Related Issue(s):

  • n/a

Proposed Changes:

  1. this malware attack caused some packages to be flagged by npm audit, but only because the github vulnerabilities had an overly loose constraint of >=0 on the versions for them, even though only one latest version was compromised. This PR pins a max version on those packages to prevent them from being used, and adds the vulnerability numbers to the audit ignore file.

PR Checklist:

  • I have added my changes to the CHANGELOG or a CHANGELOG entry is not required.

@philvarner philvarner merged commit b38dab1 into main Sep 8, 2025
4 checks passed
@philvarner philvarner deleted the pv/malware-attack-defense-and-audit-config branch September 8, 2025 19:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant