Skip to content

fix(security): refresh browser and Lambda packages - #3158

Merged
mikemcdougall merged 2 commits into
trunkfrom
fix/cesium-dompurify-audit
Aug 9, 2026
Merged

fix(security): refresh browser and Lambda packages#3158
mikemcdougall merged 2 commits into
trunkfrom
fix/cesium-dompurify-audit

Conversation

@mikemcdougall

@mikemcdougall mikemcdougall commented Aug 8, 2026

Copy link
Copy Markdown
Collaborator

Updates the Cesium browser-test lockfile from DOMPurify 3.4.12 to 3.4.13 and refreshes Amazon Linux package metadata before the Lambda image upgrade.

The lockfile update resolves GHSA-55q2-fjhq-7xh7. The Lambda refresh makes the build consume newly published fixed versions of glib2, libacl, gawk, rpm, and rpm-libs instead of stale base-image metadata.

Validated with npm ci --prefix tests/js-browser/cesium, npm audit --prefix tests/js-browser/cesium --omit=dev --audit-level=moderate, and git diff --check.

@mikemcdougall mikemcdougall changed the title fix(test): update DOMPurify security patch fix(security): refresh browser and Lambda packages Aug 8, 2026
@mikemcdougall

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Swish!

Reviewed commit: 5fc55d0723

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mikemcdougall mikemcdougall added train:landing PR in an in-flight train batch train:escalated dropped by train; needs human fix and removed train:landing PR in an in-flight train batch labels Aug 9, 2026
@mikemcdougall

Copy link
Copy Markdown
Collaborator Author

Merge train escalated this batch to a human: CI failure not attributable to a single member diff (and not autofixable). This PR is held out of future batches until the train:escalated label is removed.

@mikemcdougall mikemcdougall added train:landing PR in an in-flight train batch and removed train:escalated dropped by train; needs human fix labels Aug 9, 2026
@mikemcdougall
mikemcdougall merged commit fd1c651 into trunk Aug 9, 2026
12 of 16 checks passed
@mikemcdougall mikemcdougall removed the train:landing PR in an in-flight train batch label Aug 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant