Skip to content

fix: align canvas lockfile version metadata - #347

Open
RafaelGorski wants to merge 1 commit into
mainfrom
rafaelgorski-security-review-lockfile-metadata
Open

RafaelGorski wants to merge 1 commit into
mainfrom
rafaelgorski-security-review-lockfile-metadata

Conversation

@RafaelGorski

Copy link
Copy Markdown
Owner

Summary

  • Align the canvas extension lockfile's root and top-level package versions with package.json and VERSION (1.1.5), without upgrading dependencies.
  • Add a version-parity regression test to the default extension test suite.

No exploitable vulnerabilities or open Dependabot, CodeQL, or secret-scanning alerts were found in the point-in-time review; npm audit reported zero vulnerabilities and npm outdated reported no upgrades. This PR addresses the maintenance mismatch recorded in #346, not a security advisory.

Verification

  • npm test --prefix .github\extensions\srs-navigator (308 passing)
  • python scripts\build-plugin.py validate
  • Regression guard negative-tested against the stale 1.1.3 lockfile metadata.

Closes #346

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix lockfile/package version metadata drift and retain security-scan evidence

1 participant