Skip to content

docs(plan): scope dependency security remediation - #175

Open
dirtybits wants to merge 1 commit into
mainfrom
docs/dependency-security-remediation
Open

docs(plan): scope dependency security remediation#175
dirtybits wants to merge 1 commit into
mainfrom
docs/dependency-security-remediation

Conversation

@dirtybits

Copy link
Copy Markdown
Owner

Summary

  • add an implementation-sized remediation plan for the 2026-09-07 production npm-audit findings
  • isolate compatible direct web dependency updates from the blocked Vercel major upgrade and Anchor no-fix path
  • define lockfile review, audit reduction, full web gate, preview rollout, and rollback requirements

Documentation verification

  • YAML frontmatter parser: confirmed required name, overview, todos, and isProject fields; four concrete pending todos
  • git diff --cached --check before commit: clean
  • committed with an SSH signature (the commit payload contains gpgsig -----BEGIN SSH SIGNATURE-----; local display verification lacks gpg.ssh.allowedSignersFile)

Not run

This is documentation-only planning. No dependency versions, lockfile, application code, runtime tests, build, deployment, database, wallet, or chain behavior changed.

Follow-up

Execute the plan only after classifying direct dependency reachability and preserving the existing source/build-toolchain constraints in AGENTS.md.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant