Skip to content

security: automated dependency hardening#1226

Closed
Hardonian wants to merge 1 commit into
mainfrom
security/auto-hardening-20260719
Closed

security: automated dependency hardening#1226
Hardonian wants to merge 1 commit into
mainfrom
security/auto-hardening-20260719

Conversation

@Hardonian

Copy link
Copy Markdown
Owner

Automated weekly drift guard.

Before: │ critical │ Node-SAML SAML Signature Verification Vulnerability │
unknown
After: │ critical │ Node-SAML SAML Signature Verification Vulnerability │
unknown

Merges via auto-merge-bot once verified.

Before: │ critical            │ Node-SAML SAML Signature Verification Vulnerability    │
unknown
After:  │ critical            │ Node-SAML SAML Signature Verification Vulnerability    │
unknown
@vercel

vercel Bot commented Jul 19, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
settler Error Error Jul 19, 2026 11:55am

@github-actions

Copy link
Copy Markdown

🔒 Release Safety Check Results

Safety Checks Passed

{"code":"NOT_FOUND","message":"Requested function was not found"}

@github-actions

Copy link
Copy Markdown

🔍 Classification Check Results

⚠️ Classification report not found.
This may indicate the classification check failed.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ec134a63bb

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread package.json
Comment on lines +456 to +457
"pnpm": {
"overrides": {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Commit the lockfile update for new pnpm overrides

This adds a new root pnpm override configuration without updating pnpm-lock.yaml. In the CI workflow I checked (.github/workflows/ci.yml:49-50) installs run pnpm install --frozen-lockfile, and pnpm's --frozen-lockfile docs state that mode fails when the lockfile is out of sync with the manifest. Because the lockfile's overrides: section still contains only the previous entries and none of these new selectors, frozen installs for this commit will reject the checkout with an overrides config mismatch; please regenerate and commit pnpm-lock.yaml with the manifest change.

Useful? React with 👍 / 👎.

@Hardonian

Copy link
Copy Markdown
Owner Author

Closed during PR cleanup: mergeable=UNKNOWN base=main. Reopen only with a current verified change.

@Hardonian Hardonian closed this Jul 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant