Skip to content

Novatechflow/dependabot vuln remediation#136

Open
novatechflow wants to merge 3 commits intoKafScale:mainfrom
novatechflow:novatechflow/dependabot-vuln-remediation
Open

Novatechflow/dependabot vuln remediation#136
novatechflow wants to merge 3 commits intoKafScale:mainfrom
novatechflow:novatechflow/dependabot-vuln-remediation

Conversation

@novatechflow
Copy link
Collaborator

Summary

  • Remediates fixable Dependabot vulnerabilities in Go and npm dependencies.
  • Addresses multiple open Code Scanning findings (CodeQL + Scorecard) in code, workflows, and Dockerfiles.
  • Keeps @aws-sdk/xml-builder pinned while forcing safe transitive fast-xml-parser.

Testing

  • go test ./...
  • make test-produce-consume (broker changes)
  • make test-consumer-group (group changes)

Checklist

  • Added/updated unit tests for new logic
  • Added/updated e2e coverage for bug fixes
  • Added license headers to new files

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant