Skip to content

fix(security): Remediate open security alerts - #159

Merged
MathurAditya724 merged 1 commit into
mainfrom
codex/security-alert-remediation
Sep 6, 2026
Merged

fix(security): Remediate open security alerts#159
MathurAditya724 merged 1 commit into
mainfrom
codex/security-alert-remediation

Conversation

@MathurAditya724

Copy link
Copy Markdown
Member

Sets the CI workflow token to read-only and refreshes every affected dependency path in the pnpm and demo npm lockfiles. Direct React Router and Cloudflare tooling upgrades cover dependency paths that cannot be safely expressed as root overrides.

The lockfile refresh removes the vulnerable resolved packages while preserving the repository's existing pnpm override approach. The demo's generated worker-configuration.d.ts remains intentionally ignored, so its standalone typecheck still requires generating that file; its production build completes.

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
❌ Deployment failed
View logs
jared d2262f7 Sep 05 2026, 08:48 PM

@MathurAditya724
MathurAditya724 marked this pull request as ready for review September 6, 2026 05:19
@MathurAditya724
MathurAditya724 merged commit 49fc1c3 into main Sep 6, 2026
16 of 17 checks passed
@MathurAditya724
MathurAditya724 deleted the codex/security-alert-remediation branch September 6, 2026 05:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant