Skip to content

feat: add exclusions for new CVEs affecting dependencies and clarify usage context#9029

Merged
mohd-kashif merged 1 commit into
masterfrom
CECHO-1353
Jun 15, 2026
Merged

feat: add exclusions for new CVEs affecting dependencies and clarify usage context#9029
mohd-kashif merged 1 commit into
masterfrom
CECHO-1353

Conversation

@mohd-kashif

Copy link
Copy Markdown
Contributor

Ticket: CECHO-1353

@mohd-kashif mohd-kashif requested review from a team as code owners June 15, 2026 19:40
@linear-code

linear-code Bot commented Jun 15, 2026

Copy link
Copy Markdown

CECHO-1353

@mohd-kashif mohd-kashif self-assigned this Jun 15, 2026
@mohd-kashif mohd-kashif requested review from a team and Copilot June 15, 2026 19:40

This comment was marked as abuse.

@bhargavirao24 bhargavirao24 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving this again since it is blocking the SDK release.

That said from a Security perspective, we would prefer not to keep these CVEs ignored in the exclude path long-term. I see there is already a follow-up ticket to explore revisiting the ignored SDK advisories which should help improve this process going forward:

https://linear.app/bitgo/issue/WCN-959/explore-using-night-agent-to-revisit-ignored-sdk-advisories

@optimizedalgo optimizedalgo left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@mohd-kashif mohd-kashif merged commit ec131f7 into master Jun 15, 2026
22 of 23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants