Skip to content

Fix npm advisories and pin dependencies by hash - #8

Open
ronkq wants to merge 5 commits into
zipherscan-initfrom
pin-deps-security
Open

ronkq wants to merge 5 commits into
zipherscan-initfrom
pin-deps-security

Conversation

@ronkq

@ronkq ronkq commented Sep 24, 2026

Copy link
Copy Markdown
Collaborator

Stacked on #6.

  • Security bumps: next 16.3.0 → 16.3.6 (critical image-optimizer RCE, GHSA-2xp9-vwfh-vxw4), sharp 0.35.4, postcss 8.5.28, js-yaml 3.15.2, fflate 0.6.11. npm audit is clean.
  • Node 22.14.0 → 22.23.3 (six missed security releases).
  • Docker base images pinned by digest (node, postgres, the Dockerfile syntax frontend).
  • GitHub Actions pinned to commit SHAs; trufflehog moved off @main.
  • Python deps compiled with hashes (requirements.in → requirements.txt, installed with --require-hashes), same for pip-audit.
  • hadolint and shellcheck downloads verified by sha256.

@ronkq ronkq self-assigned this Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant