fix: pin exact dependency versions for critical packages - #575
Olayiwola2904 wants to merge 13 commits into
Conversation
|
@Olayiwola2904 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
…ions-for-critical Resolved package.json: kept this PR's exact pins and added main's yaml dependency. Synced package-lock.json root devDependencies with package.json.
|
Rebased on @dadadave80 this should be mergeable again — could you take another look? One caveat that predates the merge: Commit: 66db63f |
please fix merge issue again. |
Overview
This PR pins critical dependencies to exact versions in
package.jsonso thatbun installcannot silently pull in compromised or buggy minor/patch releases. The affected packages are@stellar/stellar-sdk,express, anddotenv, plus other security-sensitive dependencies, and the pinning strategy is documented for future maintenance.Related Issue
Closes the dependency-pinning bounty issue
Changes
🔒 Exact Dependency Pinning
[MODIFY]
package.json@stellar/stellar-sdk,express, anddotenvto exact versions.^) ranges from all critical dependencies.[MODIFY]
bun.lock/package-lock.jsonpackage.json.[ADD]
docs/adr/004-dependency-pinning.md[MODIFY]
SECURITY.md[MODIFY]
README.mdVerification Results
package.json@stellar/stellar-sdk,express, anddotenvnow use exact versionsbun.lockreflects pinned versionsdocs/adr/004-dependency-pinning.md+SECURITY.md^ranges remainingCloses #537