Skip to content

Conversation

@joao-loker
Copy link
Contributor

No description provided.

…ent (2025-09-08)

- Add overrides/resolutions to prevent installation of compromised packages
- Block [email protected], [email protected] and related malicious dependencies
- Pin to safe versions: [email protected], [email protected] and updated ANSI packages
- Applied to: plugin-NornAI, Plugin-Centaury Contents, Plugin-IconBridge

Refs:
- chalk/chalk#656
- debug-js/debug#1005
- https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised
- Update chalk from 5.6.2 to 5.6.0 (company standard)
- Update all ANSI/color packages to exact versions per guidelines
- Add missing 'color': '5.0.0' package override
- Add 'save-exact': true to prevent floating version ranges
- Applied to: plugin-NornAI, Plugin-Centaury Contents, Plugin-IconBridge

Following exact company security specifications for [email protected] [email protected] incident
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants