Skip to content

chore(deps): mitigate high audit by overriding basic-ftp#7

Closed
aretw0 wants to merge 2 commits intodevelopfrom
chore/deps-convergence-health
Closed

chore(deps): mitigate high audit by overriding basic-ftp#7
aretw0 wants to merge 2 commits intodevelopfrom
chore/deps-convergence-health

Conversation

@aretw0
Copy link
Copy Markdown
Owner

@aretw0 aretw0 commented Apr 13, 2026

Summary

  • add npm override for basic-ftp to 5.2.2
  • update lockfile accordingly
  • keep changes minimal (no bulk dependency merge)

Why

  • CI quality job fails on high advisory for basic-ftp <= 5.2.1
  • this mitigation removes high severity without forcing major dependency shifts

Tracking

Validation

  • local hook checks passed on feature branch (lint/type-check/unit/advisory security)
  • npm audit now reports only moderate issues in tooling chain (yaml-language-server via @astrojs/check)

Residual risk

  • moderate yaml advisory remains and requires breaking path (npm audit fix --force)
  • propose separate controlled track for tooling-major updates

@aretw0
Copy link
Copy Markdown
Owner Author

aretw0 commented Apr 14, 2026

Closing as superseded by #8. The relevant dependency convergence changes are already merged into develop via PR #8.

@aretw0 aretw0 closed this Apr 14, 2026
@aretw0 aretw0 deleted the chore/deps-convergence-health branch April 14, 2026 20:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant