Skip to content

fix: Resolve security vulnerabilities and ignore unfixable transitive dep vulns#72

Open
anurag-stepsecurity wants to merge 1 commit intomainfrom
fix-vulns
Open

fix: Resolve security vulnerabilities and ignore unfixable transitive dep vulns#72
anurag-stepsecurity wants to merge 1 commit intomainfrom
fix-vulns

Conversation

@anurag-stepsecurity
Copy link
Copy Markdown

Description

This PR:

  • Bumps mocha to v11 in reports/mocha and reports/mochawesome test fixtures to fix minimatch, picomatch, nanoid, js-yaml, and diff vulns.
  • Adds osv-scanner.toml to ignore entries for serialize-javascript (GHSA-5c6j-r48x-rmvq, GHSA-qj8w-gfj5-8c6v) in mocha and mochawesome fixtures — unfixable transitive dep of mocha 8-12.
  • Added root osv-scanner.toml to ignore 5 undici vulns — transitive dep not directly used by the action.

@anurag-stepsecurity anurag-stepsecurity marked this pull request as draft April 9, 2026 12:05
Signed-off-by: Anurag Rajawat <anurag@stepsecurity.io>
@anurag-stepsecurity anurag-stepsecurity marked this pull request as ready for review April 9, 2026 12:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant