Skip to content

zarf/0.67.0-r0: cve remediation#75221

Closed
octo-sts[bot] wants to merge 1 commit into
mainfrom
cve-zarf-0.67.0-r0-2ff7cb511ef4e3f1bcb19e07da229457
Closed

zarf/0.67.0-r0: cve remediation#75221
octo-sts[bot] wants to merge 1 commit into
mainfrom
cve-zarf-0.67.0-r0-2ff7cb511ef4e3f1bcb19e07da229457

zarf/0.67.0-r0: fix GHSA-f83f-xpx7-ffpw

8d54be7
Select commit
Loading
Failed to load commit list.
StepSecurity Actions Security / StepSecurity Required Checks succeeded Dec 8, 2025 in 1s

StepSecurity Required Checks

Finished StepSecurity Required Checks

  • Pwn Request Vulnerabilities Check - Checks for Pwn Request vulnerabilities in the PR via risky triggers
  • Script Injection Check - Checks for script injection vulnerabilities in the PR
  • NPM Compromised Packages Check - Checks for compromised npm package versions in the PR
  • NPM Package Cooldown Check - Fails if any package version in the PR was released within the configured cooldown period, helping to avoid brand-new (and potentially unreviewed or malicious) releases

Details

✅ NPM Compromised Packages Check

No Compromised npm packages are added in current PR.

✅ Pwn Request Vulnerabilities Check

No Pwn Request vulnerabilities found in this PR.

✅ Script Injection Vulnerabilities Check

No Script Injection vulnerabilities found in this PR.

✅ NPM Package Cooldown Check

No npm package upgrades to recent releases found in current PR.

⏲️ History

Previous invocation results of same check: