Skip to content

Conversation

@manasag
Copy link
Contributor

@manasag manasag commented Jan 23, 2026

Gokakashi is deprecated, hence workflow file update. Btw we should add the new security agent integration to the CI/CD, as a follow up task.

Also npm audit fixes

# npm audit report

diff  <4.0.4 || >=5.0.0 <5.2.2
jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch - https://github.com/advisories/GHSA-73rr-hh4g-fpgx
jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch - https://github.com/advisories/GHSA-73rr-hh4g-fpgx
fix available via `npm audit fix`
node_modules/diff
node_modules/mocha/node_modules/diff

glob  11.0.0 - 11.0.3
Severity: high
glob CLI: Command injection via -c/--cmd executes matches with shell:true - https://github.com/advisories/GHSA-5j98-mcp5-4vw2
fix available via `npm audit fix`
node_modules/@hasura/ts-node-dev/node_modules/glob

js-yaml  4.0.0 - 4.1.0
Severity: moderate
js-yaml has prototype pollution in merge (<<) - https://github.com/advisories/GHSA-mh29-5h37-fv8m
fix available via `npm audit fix`
node_modules/js-yaml

3 vulnerabilities (1 low, 1 moderate, 1 high)

@manasag manasag merged commit 12a9c99 into main Jan 23, 2026
4 checks passed
@manasag manasag deleted the manas/ts-sdk-update branch January 23, 2026 07:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants