Skip to content

Bump @linearb/gitstream-core to 2.1.230#527

Closed
linearbci wants to merge 2 commits intodevelopfrom
bump-gitstream-core-to-2.1.230
Closed

Bump @linearb/gitstream-core to 2.1.230#527
linearbci wants to merge 2 commits intodevelopfrom
bump-gitstream-core-to-2.1.230

Conversation

@linearbci
Copy link
Copy Markdown
Collaborator

No description provided.

MishaKav and others added 2 commits April 20, 2026 13:38
Scope the workflow runner token to least privilege:
- bump-gitstream-core.yml: permissions: {} (uses PAT, not GITHUB_TOKEN)
- create-tag-on-merge.yml: contents: write + pull-requests: read

Follows https://github.blog/changelog/2021-04-20-github-actions-control-permissions-for-github_token/
@linearbci linearbci requested a review from MishaKav April 20, 2026 10:41
Copy link
Copy Markdown

@orca-security-us orca-security-us bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Orca Security Scan Summary

Status Check Issues by priority
Passed Passed Infrastructure as Code high 0   medium 0   low 0   info 0 View in Orca
Passed Passed OSS Licenses high 0   medium 0   low 0   info 0 View in Orca
Passed Passed SAST high 0   medium 0   low 0   info 0 View in Orca
Passed Passed Secrets high 0   medium 0   low 0   info 0 View in Orca
Failed Failed Vulnerabilities high 4   medium 0   low 0   info 0 View in Orca
☢️ The following Vulnerabilities (CVEs) have been detected
PACKAGE FILE CVE ID INSTALLED VERSION FIXED VERSION
critical undici ./package-lock.json CVE-2026-1525 5.29.0 6.24.0, 7.24.0 View in code
high undici ./package-lock.json CVE-2026-1526 5.29.0 6.24.0, 7.24.0 View in code
high undici ./package-lock.json CVE-2026-2229 5.29.0 6.24.0, 7.24.0 View in code
high undici ./package-lock.json CVE-2026-22036 5.29.0 7.18.2, 6.23.0 View in code

@MishaKav MishaKav closed this Apr 20, 2026
@MishaKav MishaKav deleted the bump-gitstream-core-to-2.1.230 branch April 20, 2026 10:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants