Skip to content

Fix Dependabot vulnerabilities and add CODE_OF_CONDUCT.md - #485

Open
jeff-at-trimble with Copilot wants to merge 3 commits into
mainfrom
copilot/fix-dependabot-vulnerabilities-again
Open

jeff-at-trimble with Copilot wants to merge 3 commits into
mainfrom
copilot/fix-dependabot-vulnerabilities-again

Conversation

Copilot AI commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Addresses the OSS compliance findings: high/critical Dependabot alerts must be zero, and the recommended CODE_OF_CONDUCT.md was missing.

Changes

  • package-lock.json — npm audit fix clears every patchable advisory (critical shell-quote injection; high browserslist, fast-uri, js-yaml, source-map-js, brace-expansion; plus moderates). package.json version ranges are untouched to avoid the bogus major downgrades --force proposes (e.g. stylelint@7, which breaks lint-css).
  • CODE_OF_CONDUCT.md — Contributor Covenant v2.1, with the dev guidelines working group (dev-guidelines-working-group-ug@trimble.com, per content/governance.md) as enforcement contact.

Remaining alert

One high advisory persists and cannot be resolved by a version bump: braces (GHSA-vfj7-8cjw-p6xm), reached transitively via stylelint → micromatch. The advisory affects <= 3.0.3 (the latest release) with first_patched_version: null, so there is no upgrade/override target. It will clear once upstream publishes a fix.

Copilot AI and others added 2 commits October 7, 2026 20:23
Co-authored-by: jeff-at-trimble <215895768+jeff-at-trimble@users.noreply.github.com>
Co-authored-by: jeff-at-trimble <215895768+jeff-at-trimble@users.noreply.github.com>
@jeff-at-trimble
jeff-at-trimble marked this pull request as ready for review October 7, 2026 20:25
@jeff-at-trimble
jeff-at-trimble self-requested a review as a code owner October 7, 2026 20:25
Copilot AI changed the title [WIP] Fix Dependabot vulnerabilities to meet policy compliance Fix Dependabot vulnerabilities and add CODE_OF_CONDUCT.md Oct 7, 2026
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

Super-linter summary

Language Validation result
GITLEAKS Pass ✅
GIT_MERGE_CONFLICT_MARKERS Pass ✅
JSON Pass ✅
JSON_PRETTIER Pass ✅
MARKDOWN Pass ✅
MARKDOWN_PRETTIER Pass ✅
PRE_COMMIT Pass ✅
SPELL_CODESPELL Pass ✅
TRIVY Pass ✅

All files and directories linted successfully

For more information, see the GitHub Actions workflow run

Powered by Super-linter

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

🚨 Policy Compliance Violation — Action Required

2 participants