Skip to content

deps: refresh npm lockfiles and patch jsdiff CVE - #6119

Open
replicated-software-factory[bot] wants to merge 1 commit into
mainfrom
deps/kurl-update-npm
Open

deps: refresh npm lockfiles and patch jsdiff CVE#6119
replicated-software-factory[bot] wants to merge 1 commit into
mainfrom
deps/kurl-update-npm

Conversation

@replicated-software-factory

Copy link
Copy Markdown
Contributor

Refresh transitive dependencies across all npm projects and override jsdiff (^8.0.3) in mocha-based dev trees to resolve GHSA-73rr-hh4g-fpgx.

Projects updated:

  • Root package-lock.json
  • bin/scan-images/package.json and package-lock.json
  • .github/actions/import-external-addons/package.json and package-lock.json
  • .github/actions/testgrid-checker/package-lock.json and dist/index.js

Validation:

  • npm audit passes with 0 vulnerabilities in all four npm projects
  • bin/scan-images tests pass
  • import-external-addons tests and build pass
  • testgrid-checker build passes

Refresh transitive dependencies across all npm projects and override
jsdiff (^8.0.3) in mocha-based dev trees to resolve GHSA-73rr-hh4g-fpgx.

- package-lock.json (root)
- bin/scan-images/package{,-lock}.json
- .github/actions/import-external-addons/package{,-lock}.json
- .github/actions/testgrid-checker/package-lock.json + dist/index.js

All npm audits pass and affected tests/builds succeed.
@replicated-software-factory
replicated-software-factory Bot requested a review from a team as a code owner August 30, 2026 19:05
@greptile-apps

greptile-apps Bot commented Aug 30, 2026

Copy link
Copy Markdown

Reviews (1): Last reviewed commit: "deps: refresh npm lockfiles and patch js..." | Re-trigger Greptile

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants