Skip to content

fix(status): permit HTTPS remote origins for polling & SSE, remediate source-map-js CVE - #255

Merged
KbWen merged 2 commits into
mainfrom
fix/https-status-and-security-audit
Oct 7, 2026
Merged

KbWen merged 2 commits into
mainfrom
fix/https-status-and-security-audit

Conversation

@KbWen

@KbWen KbWen commented Oct 7, 2026

Copy link
Copy Markdown
Owner

Summary

  • Allow remote HTTPS origins for polling and SSE in src/inference/inferStatus.js (remediating false suppression under TLS reverse-proxy / HTTPS domains).
  • Pin source-map-js to ^1.2.2 via package.json overrides to eliminate GHSA-68fv-2mgg-jv7q high-severity ReDoS CVE.
  • Add regression test ests/httpsStatusIntegration.test.js.
  • Update Agentic OS SSoT and archive work log.

Verification

  • 151 test suites passed (2,714 passed, 0 failed)
  • npm audit: 0 vulnerabilities
  • smoke:pack: 4/4 assertions PASS
  • validate.ps1: 115 pass, 0 fail

@KbWen
KbWen merged commit 405136f into main Oct 7, 2026
8 checks passed
@KbWen
KbWen deleted the fix/https-status-and-security-audit branch October 7, 2026 10:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant