Skip to content

fix(CVE) - #8

Merged
mello-sdn merged 2 commits into
mainfrom
fix/pipeline
Jul 25, 2026
Merged

mello-sdn merged 2 commits into
mainfrom
fix/pipeline

Conversation

@mello-sdn

Copy link
Copy Markdown
Owner

Resolve CVE-2026-14257 (brace-expansion HIGH) by overriding bundled dependency in Docker image (the node:26-alpine base image come with npm 11.17.0 which bundles vulnerable versions of brace-expansion@5.0.6) and remove redundant 'node' and 'npm' from package.json dependencies

@mello-sdn
mello-sdn merged commit 98072a9 into main Jul 25, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant