Remove @neondatabase/api-client and neonctl to address CVE-2026-25639 (axios supply chain vulnerability). Pin all JS dependencies to exact versions across all package.json files to prevent future supply chain attacks via semver range resolution. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| .grype.yaml | ||
| baseline_db.py | ||
| check_file_length.py | ||
| check_files_match.py | ||
| publish-proxy-extras.sh | ||
| run_migration.py | ||
| security_scans_readme.md | ||
| security_scans.sh | ||
| TEST_KEY_PATTERNS.md | ||