Skip to content

fix(security): resolve Dependabot and token-permission alerts - #61

Merged
SafetyMP merged 1 commit into
mainfrom
fix/security-alerts-2026-09
Sep 5, 2026
Merged

fix(security): resolve Dependabot and token-permission alerts#61
SafetyMP merged 1 commit into
mainfrom
fix/security-alerts-2026-09

Conversation

@SafetyMP

@SafetyMP SafetyMP commented Sep 5, 2026

Copy link
Copy Markdown
Owner

Summary

CorpOS is a reference architecture, not a production SaaS. This PR only closes the actionable GitHub security alerts on main without landing Vite 8, Zod 4, or nanoid 6.

Skipped

Test plan

Made with Cursor

Main still shipped vulnerable transitives and top-level write tokens.
Override fast-uri 3.1.7 and qs 6.16.0, pin the node image digest, and
scope security-events/packages writes to the jobs that need them.

Co-authored-by: Cursor <cursoragent@cursor.com>
@SafetyMP
SafetyMP merged commit 851c499 into main Sep 5, 2026
3 checks passed
@SafetyMP
SafetyMP deleted the fix/security-alerts-2026-09 branch September 5, 2026 17:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant