Skip to content

Conversation

@anu3990
Copy link
Contributor

@anu3990 anu3990 commented Oct 1, 2025

No description provided.

@anu3990 anu3990 requested review from Copilot and removed request for BillFarber, rjrudin and stevebio October 1, 2025 05:19
@github-actions
Copy link

github-actions bot commented Oct 1, 2025

Copyright Validation Results
Total: 2 | Passed: 0 | Failed: 0 | Skipped: 2 | at: 2025-10-01 05:19:25 UTC | commit: 6115428

⏭️ Skipped (Excluded) Files

  • package-lock.json
  • package.json

✅ All files have valid copyright headers!

Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR addresses a supply chain security vulnerability by updating the mocha testing framework and adding package overrides to pin specific dependency versions to prevent malicious package substitution attacks.

  • Updated mocha from version ^10.0.0 to ^11.7.3
  • Added multiple package overrides to lock down transitive dependencies at secure versions

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

@anu3990 anu3990 merged commit 1124a2f into marklogic:develop Oct 1, 2025
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants