Skip to content

[MGMT-358] Bump vulnerable transitive deps (adzerk-api-specification) - #121

Open
honeycomb-cheesecake wants to merge 3 commits into
masterfrom
MGMT-358-bump-vulnerable-deps
Open

[MGMT-358] Bump vulnerable transitive deps (adzerk-api-specification)#121
honeycomb-cheesecake wants to merge 3 commits into
masterfrom
MGMT-358-bump-vulnerable-deps

Conversation

@honeycomb-cheesecake

Copy link
Copy Markdown
Contributor

Summary

Resolves Datadog-flagged CVE findings for MGMT-358.

Fixed

  • ip-address 10.2.0, brace-expansion 5.0.6, shell-quote 1.8.4 — all transitive via @openapitools/openapi-generator-cli. Bumped that devDependency within its existing ^2.15.3 range via npm audit fix (2.39.1 → 2.40.1). package.json unchanged, only package-lock.json.

Not fixed

None — all 7 flagged findings resolved with a non-breaking bump.

Verification

npm audit → 0 vulnerabilities. npm run validate-decision (openapi-generator-cli validate) passes.

Simon Ramzi added 3 commits August 17, 2026 11:24
…sories

npm audit fix resolves ip-address, brace-expansion, and shell-quote
advisories flagged by Datadog (via concurrently -> openapi-generator-cli),
all within the existing ^2.15.3 devDependency range.
Documents the CHANGELOG update, decision-spec validation/build, and
management-spec validation + Swagger Merger dangling-$ref check steps
that should follow any spec change in this repo.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant