Skip to content

fix(security): remediate July ECR runtime CVEs - #32

Merged
jmgasper merged 1 commit into
developfrom
security_july_2026
Jul 20, 2026
Merged

fix(security): remediate July ECR runtime CVEs#32
jmgasper merged 1 commit into
developfrom
security_july_2026

Conversation

@jmgasper

Copy link
Copy Markdown
Contributor

Upgrade and constrain runtime dependencies for Axios CVE-2025-62718/CVE-2026-42043/CVE-2026-44496, Hono CVE-2026-29045/CVE-2026-54290, Multer CVE-2026-2359/CVE-2026-3520, Lodash CVE-2026-4800, Nest CVE-2026-35515, and related Critical/High/Medium findings.

Use a clean production dependency stage and remove npm from the runtime image to eliminate Sigstore CVE-2026-48815, tar CVE-2026-53655, and build-tool-only findings. Pin the known-clean Node 22.23.1 Alpine base and upgrade OS packages.

Upgrade and constrain runtime dependencies for Axios CVE-2025-62718/CVE-2026-42043/CVE-2026-44496, Hono CVE-2026-29045/CVE-2026-54290, Multer CVE-2026-2359/CVE-2026-3520, Lodash CVE-2026-4800, Nest CVE-2026-35515, and related Critical/High/Medium findings.

Use a clean production dependency stage and remove npm from the runtime image to eliminate Sigstore CVE-2026-48815, tar CVE-2026-53655, and build-tool-only findings. Pin the known-clean Node 22.23.1 Alpine base and upgrade OS packages.
@jmgasper
jmgasper merged commit 1ece2ee into develop Jul 20, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant