Skip to content

ECR and dependabot alert fixes, latest Node version - #34

Merged
jmgasper merged 7 commits into
masterfrom
develop
Jul 28, 2026
Merged

ECR and dependabot alert fixes, latest Node version#34
jmgasper merged 7 commits into
masterfrom
develop

Conversation

@jmgasper

Copy link
Copy Markdown
Contributor

No description provided.

jmgasper added 7 commits July 15, 2026 14:59
Upgrade and constrain runtime dependencies for Axios CVE-2025-62718/CVE-2026-42043/CVE-2026-44496, Hono CVE-2026-29045/CVE-2026-54290, Multer CVE-2026-2359/CVE-2026-3520, Lodash CVE-2026-4800, Nest CVE-2026-35515, and related Critical/High/Medium findings.

Use a clean production dependency stage and remove npm from the runtime image to eliminate Sigstore CVE-2026-48815, tar CVE-2026-53655, and build-tool-only findings. Pin the known-clean Node 22.23.1 Alpine base and upgrade OS packages.
fix(security): remediate July ECR runtime CVEs
fix(security): resolve Dependabot alerts
@jmgasper
jmgasper merged commit 52b94d0 into master Jul 28, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant