INFRA-130: add Dependabot coverage and clear ws/form-data highs #80

Merged
amoussa1229 merged 1 commit from INFRA-130-dependabot-coverage into main 2026-07-08 20:53:34 +00:00
amoussa1229 commented 2026-07-08 20:31:48 +00:00 (Migrated from github.com)

Adds .github/dependabot.yml covering all ecosystems: npm (root and /services/socket-mode), docker (/services/socket-mode), and github-actions. Follows the org grouped minor/patch idiom.

Also clears the two open HIGH runtime alerts in services/socket-mode via npm audit fix (package-lock.json only, no major bumps, package.json unchanged):

  • form-data 4.0.5 -> 4.0.6 (GHSA-hmw2-7cc7-3qxx, CRLF injection)
  • ws 8.20.0 -> 8.21.0 (GHSA-96hv-2xvq-fx4p, memory-exhaustion DoS)

npm audit in that workspace now reports 0 vulnerabilities.

Part of INFRA-130 (close Dependabot config coverage gaps).

Adds `.github/dependabot.yml` covering all ecosystems: npm (root and `/services/socket-mode`), docker (`/services/socket-mode`), and github-actions. Follows the org grouped minor/patch idiom. Also clears the two open HIGH runtime alerts in `services/socket-mode` via `npm audit fix` (package-lock.json only, no major bumps, package.json unchanged): - form-data 4.0.5 -> 4.0.6 (GHSA-hmw2-7cc7-3qxx, CRLF injection) - ws 8.20.0 -> 8.21.0 (GHSA-96hv-2xvq-fx4p, memory-exhaustion DoS) `npm audit` in that workspace now reports 0 vulnerabilities. Part of INFRA-130 (close Dependabot config coverage gaps).
seahaven-openswe[bot] (Migrated from github.com) reviewed 2026-07-08 20:33:44 +00:00
seahaven-openswe[bot] (Migrated from github.com) left a comment

✅ Open SWE Review: No issues found

Open SWE reviewed this PR and found no potential bugs to report.

Open in Web

## ✅ Open SWE Review: No issues found Open SWE reviewed this PR and found no potential bugs to report. [Open in Web](https://openswe.seahaven.com/agents/reviews/Sea-Haven-Industries/seahaven-slack-bot/80) <!-- open-swe-reviewer pr=80 -->
This repo is archived. You cannot comment on pull requests.
No description provided.