Skip to content

feat(ee): merge Workspace into the monorepo as a built-in extension - #3455

Merged
ToddHebebrand merged 22 commits into
mainfrom
ToddHebebrand/workspace-ee-merge
Aug 12, 2026
Merged

feat(ee): merge Workspace into the monorepo as a built-in extension#3455
ToddHebebrand merged 22 commits into
mainfrom
ToddHebebrand/workspace-ee-merge

fix(ci): boot-step shutdown watches the process group and ignores zom…

588e8a4
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / Trivy succeeded Aug 12, 2026 in 2s

4 new alerts including 3 medium severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 3 medium
  • 1 low

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) Medium

Package: @hono/node-server
Installed Version: 1.19.17
Vulnerability GHSA-frvp-7c67-39w9
Severity: MEDIUM
Fixed Version: 2.0.5
Link: GHSA-frvp-7c67-39w9

Check warning on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

postcss: PostCSS: Information disclosure via crafted sourceMappingURL Medium

Package: postcss
Installed Version: 8.5.19
Vulnerability CVE-2026-69153
Severity: MEDIUM
Fixed Version: 8.5.23
Link: CVE-2026-69153

Check warning on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS Medium

Package: dompurify
Installed Version: 3.4.11
Vulnerability GHSA-55q2-fjhq-7xh7
Severity: MEDIUM
Fixed Version: 3.4.13
Link: GHSA-55q2-fjhq-7xh7

Check notice on line 1 in pnpm-lock.yaml

See this annotation in the file changed.

Code scanning / Trivy

DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements. Low

Package: dompurify
Installed Version: 3.4.11
Vulnerability GHSA-c2j3-45gr-mqc4
Severity: LOW
Fixed Version: 3.4.12
Link: GHSA-c2j3-45gr-mqc4