Skip to content

security: vulnerability remediation#16

Closed
kernel-internal[bot] wants to merge 3 commits into
mainfrom
security/vuln-remediation
Closed

security: vulnerability remediation#16
kernel-internal[bot] wants to merge 3 commits into
mainfrom
security/vuln-remediation

Conversation

@kernel-internal

@kernel-internal kernel-internal Bot commented May 20, 2026

Copy link
Copy Markdown

Vulnerability Remediation — 2026-05-27

Fixed

CVE Package Ecosystem Old Version New Version Manifest
N/A protobufjs npm 7.5.4 7.6.1 package-lock.json

Skipped (non-actionable)

Alert Type Package Severity Reason
criticalCVE handlebars warn Development-only dependency through ts-jest (dev dependency), not part of production runtime

Deferred (needs human review)

CVE Package Severity Reason
(none)

Co-authored-by: Cursor <cursoragent@cursor.com>
@firetiger-agent

Copy link
Copy Markdown

Firetiger deploy monitoring skipped

This PR didn't match the auto-monitor filter configured on your GitHub connection:

Any PR that changes the kernel API. Monitor changes to API endpoints (packages/api/cmd/api/) and Temporal workflows (packages/api/lib/temporal) in the kernel repo

Reason: PR only updates dependencies in lockfiles; does not modify API endpoints or Temporal workflows.

To monitor this PR anyway, reply with @firetiger monitor this.

kernel-internal Bot and others added 2 commits May 27, 2026 04:34
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant