Skip to content

chore: pin all package.json deps to exact versions, update vitest, fix 6 audit vulnerabilities#534

Closed
Copilot wants to merge 3 commits intomainfrom
copilot/fix-package-json-dependencies
Closed

chore: pin all package.json deps to exact versions, update vitest, fix 6 audit vulnerabilities#534
Copilot wants to merge 3 commits intomainfrom
copilot/fix-package-json-dependencies

Conversation

Copy link
Copy Markdown
Contributor

Copilot AI commented Mar 27, 2026

  • Analyze current state: ZAP issue ZAP Full Scan Report #320 open, package deps fixed in previous session
  • Fix CSP meta tag: remove invalid frame-ancestors 'none' (ZAP "CSP: Meta Policy Invalid Directive") and add explicit object-src 'none'
  • Update security-headers tests to reflect CSP change
  • Update SECURITY_HEADERS.md documentation
  • Improve App.tsx test coverage (currently 62.27% stmts / 58.54% branches) for non-Three.js branches
  • Run lint + tests to validate all changes

🔒 GitHub Advanced Security automatically protects Copilot coding agent pull requests. You can protect all pull requests by enabling Advanced Security for your repositories. Learn more about Advanced Security.

Agent-Logs-Url: https://github.com/Hack23/game/sessions/78cfa53f-4d33-41ca-b37b-8cd3b8603f19

Co-authored-by: pethers <1726836+pethers@users.noreply.github.com>
…audit vulnerabilities via overrides

Agent-Logs-Url: https://github.com/Hack23/game/sessions/32c5c444-f4fb-42d4-bfee-77d758555663

Co-authored-by: pethers <1726836+pethers@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix all versions in package.json dependencies chore: pin all package.json deps to exact versions, update vitest, fix 6 audit vulnerabilities Mar 27, 2026
@pethers pethers closed this Mar 27, 2026
@pethers pethers deleted the copilot/fix-package-json-dependencies branch March 27, 2026 11:55
Copilot stopped work on behalf of pethers due to an error March 27, 2026 11:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates infrastructure CI/CD and build infrastructure

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants