generated from bfra-me/.github
-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Description
Daily Autohealing Report — 2026-03-26 (UTC)
Errored PRs
None. All open PRs have passing CI checks:
Security
- Fixed: Created #3022 to address CVE-2026-33532 (yaml package Stack Overflow vulnerability).
- Vulnerability: yaml >= 2.0.0, < 2.8.3 is vulnerable to Stack Overflow via deeply nested YAML collections
- Fix: Added `yaml: >=2.8.3` override to package.json
- yaml is a transitive dependency via eslint-plugin-json-schema-validator > yaml-eslint-parser
Health & Maintenance
- Workflow Actions: All actions are pinned to commit SHAs with version comments. No unpinned actions found.
- Open Dependency Update PRs (awaiting review):
Developer Experience
All validation commands pass on main:
- `pnpm bootstrap` ✓
- `pnpm check-types` ✓
- `pnpm lint` ✓
- `pnpm check-format` ✓
Needs Human Attention
- #3022: Security fix for yaml vulnerability (CVE-2026-33532) - needs review and merge.
- #3014 and #2997: Dependency update PRs are ready for merge but require review approval.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels