Skip to content

fix: supply chain hardening and dep fixes#341

Merged
grandizzy merged 2 commits intomainfrom
fix/supply-chain-hardening
Apr 24, 2026
Merged

fix: supply chain hardening and dep fixes#341
grandizzy merged 2 commits intomainfrom
fix/supply-chain-hardening

Conversation

@grandizzy
Copy link
Copy Markdown
Contributor

@grandizzy grandizzy commented Apr 23, 2026

Override protobufjs >=7.5.5, tar >=7.5.13, dompurify >=3.4.0, move protobufjs to ignoredBuiltDependencies, and add --frozen-lockfile to CI. 24 → 5 vulns, 0 Critical.

- Override protobufjs >=7.5.5, tar >=7.5.13, dompurify >=3.4.0
- Move protobufjs to ignoredBuiltDependencies
- Add --frozen-lockfile to CI install steps
- Refresh lockfile

Co-Authored-By: grandizzy <38490174+grandizzy@users.noreply.github.com>
@grandizzy grandizzy self-assigned this Apr 23, 2026
@vercel
Copy link
Copy Markdown

vercel Bot commented Apr 23, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
tempo-docs Ready Ready Preview, Comment Apr 24, 2026 3:42am

Request Review

@grandizzy grandizzy marked this pull request as ready for review April 23, 2026 11:29
@grandizzy grandizzy requested review from jxom and tmm April 23, 2026 11:29
@grandizzy grandizzy merged commit 0c19cf7 into main Apr 24, 2026
7 of 9 checks passed
@grandizzy grandizzy deleted the fix/supply-chain-hardening branch April 24, 2026 03:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants