-
Notifications
You must be signed in to change notification settings - Fork 91
Closed
Labels
internalFor changes that affect the project's internal workings but not its outward-facing functionality.For changes that affect the project's internal workings but not its outward-facing functionality.
Milestone
Description
Issue
The newman package has been compromised in a supply chain attack. All CI workflows using Newman must be disabled immediately to prevent execution of potentially malicious code.
Action Taken
- All CI workflows containing Newman have been disabled
- Newman execution paths have been commented out with security warnings
- DO NOT UPDATE newman package
Next Steps
- Identify and evaluate secure alternatives to Newman for API testing
- Update CI workflows with the chosen alternative
- Remove Newman dependency once replacement is verified
Metadata
Metadata
Assignees
Labels
internalFor changes that affect the project's internal workings but not its outward-facing functionality.For changes that affect the project's internal workings but not its outward-facing functionality.