Skip to content

Merge security/chalk-mal-2025-46969 - #259

Merged
rahulpsq merged 2 commits into
sdk_v9_pre_prodfrom
security/chalk-mal-2025-46969
Sep 30, 2026
Merged

rahulpsq merged 2 commits into
sdk_v9_pre_prodfrom
security/chalk-mal-2025-46969

Conversation

@bsautomation

Copy link
Copy Markdown
Contributor

Merge into sdk_v9_pre_prod :by automationbs

Kamalpreet Kaur and others added 2 commits September 29, 2026 20:10
chalk@5.6.1 was published by a hijacked maintainer account
(GHSA-2v46-p5h4-248w / MAL-2025-46969). chalk is an external runtime
dependency of the service, so consumers resolve it against our declared
range; ^5.3.0 still admits 5.6.1 from any mirror or cache that retained it.
The lockfile already resolves 5.6.2, so the installed tree is unchanged.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@bsautomation
bsautomation requested a review from a team as a code owner September 30, 2026 13:00
@bsautomation
bsautomation requested review from AakashHotchandani and yashdsaraf and removed request for a team September 30, 2026 13:00
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited), Workspace UI (inherited)

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 863db031-081b-4a49-aa8d-ad0e37122230

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@rahulpsq
rahulpsq merged commit 85b672b into sdk_v9_pre_prod Sep 30, 2026
25 of 33 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants