[APPS-8012]OpEx CVE - Removed eslint and upgraded standard#124
Merged
satish-bhamare merged 1 commit intomasterfrom Feb 12, 2026
Merged
[APPS-8012]OpEx CVE - Removed eslint and upgraded standard#124satish-bhamare merged 1 commit intomasterfrom
satish-bhamare merged 1 commit intomasterfrom
Conversation
mmassaki
approved these changes
Feb 11, 2026
Contributor
mmassaki
left a comment
There was a problem hiding this comment.
I guess that .eslintrc was added to customize some rules given that standard uses eslint under the hood.
I agree with the approach of this PR and we should follow standard out of the box.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CVE exists in the
tmpmodule which is a transitive dependency introduced viaeslintandstandardThe
v2_repl_apprepo includes botheslintandstandardas dev-dependencies. However,eslintis not utilized(ref) for linting purposes instead,standardis used.Solution (purely in the context of fixing the CVE):
eslintas a dev-dependency.standardto the latest version. Since it’s a zero-configuration tool with a fixed set of rules, we’re don’t manage any configs for it. It can be upgraded without any breaking change.