Skip to content

fix: remediate critical and high npm vulnerabilities - #159

Open
thomasrockhu-codecov wants to merge 1 commit into
mainfrom
th/browser-extension-gh-cve
Open

fix: remediate critical and high npm vulnerabilities#159
thomasrockhu-codecov wants to merge 1 commit into
mainfrom
th/browser-extension-gh-cve

Conversation

@thomasrockhu-codecov

@thomasrockhu-codecov thomasrockhu-codecov commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Summary

  • refresh the npm lockfile to patched releases for all open critical and high Dependabot alerts
  • upgrade Codecov, Sentry, copy-webpack, and web-ext build tooling to unblock patched transitive dependencies
  • override stale firefox-profile and fx-runner constraints for adm-zip and shell-quote

Security impact

  • Dependabot baseline: 1 critical / 22 high
  • PR branch lockfile: 0 critical / 0 high projected, with no residuals
  • Local npm audit: 0 vulnerabilities
  • Dependabot REST API remains at the default-branch baseline until merge

Test plan

  • npm ci
  • npm run build
  • npm run build:firefox
  • npm audit
  • CI and CodeQL

Upgrade build tooling and override stale transitive constraints so critical and high Dependabot findings resolve to patched releases.
@codecov

codecov Bot commented Aug 2, 2026

Copy link
Copy Markdown

Bundle Report

Changes will increase total bundle size by 11.47kB (1.77%) ⬆️. This is within the configured threshold ✅

Detailed changes
Bundle name Size Change
codecov-browser-extension-array-push 660.55kB 11.47kB (1.77%) ⬆️

Affected Assets, Files, and Routes:

view changes for bundle: codecov-browser-extension-array-push

Assets Changed:

Asset Name Size Change Total Size Change (%)
vendor.js 668 bytes 383.92kB 0.17%
background.js 9.36kB 207.75kB 4.72%
popup.js 1.55kB 27.43kB 6.01% ⚠️
githubFile.js -36 bytes 11.46kB -0.31%
githubPR.js 8 bytes 7.84kB 0.1%
../consent.js -12 bytes 1.09kB -1.09%
options.js -71 bytes 453 bytes -13.55%

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant