Skip to content

Commit be35db7

Browse files
authored
chore(dep): Resolve dependency vulnerabilities (#343)
1 parent 97eaac7 commit be35db7

3 files changed

Lines changed: 230 additions & 214 deletions

File tree

.nsprc

Lines changed: 0 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,4 @@
11
{
2-
"GHSA-2g4f-4pwh-qvx6": {
3-
"notes": "ajv ReDoS when using $data option. Accepted risk: dev-only transitive dependency (@jupyterlab/settingregistry, table), fix requires ajv@8.18.0 but consumers are on 6.x, not bundled in extension.",
4-
"expiry": "2026-08-15"
5-
},
6-
"GHSA-3ppc-4f35-3m26": {
7-
"notes": "minimatch ReDoS via repeated wildcards. Accepted risk: dev-only transitive dependency (mocha, glob, @vscode/test-cli), fix requires minimatch@10.2.1 but consumers are on 3.x-5.x, not bundled in extension.",
8-
"expiry": "2026-08-15"
9-
},
102
"GHSA-848j-6mx2-7j84": {
113
"notes": "CVE-2025-14505: elliptic ECDSA signature corruption can lead to private key recovery if attacker obtains both faulty and correct signatures for identical inputs. Accepted risk: dev-only transitive dependency (node-stdlib-browser -> crypto-browserify -> browserify-sign), not used for signing in this project, no fix available.",
124
"expiry": "2026-08-15"

0 commit comments

Comments
 (0)