Skip to content

fix(agentex-ui): bump source-map-js 1.2.1 -> 1.2.2 (CVE-2026-93749) - #467

Open
scale-prodsec[bot] wants to merge 1 commit into
mainfrom
vulnmanagementagent/gfdvr-163487-trivy-remediate-source-map-js121-vulnerabilities
Open

scale-prodsec[bot] wants to merge 1 commit into
mainfrom
vulnmanagementagent/gfdvr-163487-trivy-remediate-source-map-js121-vulnerabilities

Conversation

@scale-prodsec

@scale-prodsec scale-prodsec Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Bump transitive source-map-js 1.2.1 -> 1.2.2 in agentex-ui/package-lock.json (smallest safe hop; 1.2.2 is the latest release and has zero OSV advisories).
  • All parent ranges are caret (^1.0.1/^1.2.0/^1.2.1), so no manifest change is needed; the lock diff is only the source-map-js entry.

Coverage

Tickets: GFDVR-163487 (https://linear.app/scale-epd/issue/GFDVR-163487)
CVEs: CVE-2026-93749

Validation

  • python -m bot.version_gate --ecosystem npm --package source-map-js --candidate 1.2.2 -> no known vulnerabilities
  • npm update source-map-js --package-lock-only in agentex-ui -> 4 insertions/3 deletions, resolved URL stays npmjs
  • npm ci --dry-run in agentex-ui -> succeeds
  • Image built from agentex-ui/Dockerfile uses npm ci against this lockfile

@scale-prodsec
scale-prodsec Bot requested a review from a team as a code owner October 6, 2026 06:29
@greptile-apps

greptile-apps Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

No reviewable files after applying ignore patterns.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants