Dependency Security and CI Enforcement #8
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This issue covers dependency security and CI enforcement.
Problems:
path-to-regexpReDoS vulnerability via its lockfile/dependency treeFiles:
Acceptance criteria:
npm auditfor Budget no longer reportspath-to-regexp <0.1.13Fixed in
4ecd233— Added .gitea/workflows/security.yml: dependency audit, secret scanning, Dockerfile lint. Requires Gitea Actions runner to execute.