Skip to content

validation dto of all endpoints - #31

Merged
LaGodxy merged 9 commits into
MettaChain:mainfrom
rosemary21:validation-dto
Jan 31, 2026
Merged

validation dto of all endpoints#31
LaGodxy merged 9 commits into
MettaChain:mainfrom
rosemary21:validation-dto

fix: ensure notify job always runs instead of being skipped

9f2e0c0
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / Trivy succeeded Jan 31, 2026 in 2s

5 new alerts including 3 medium severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 3 medium
  • 2 low

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 13798 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

js-yaml: js-yaml prototype pollution in merge Medium

Package: js-yaml
Installed Version: 4.1.0
Vulnerability CVE-2025-64718
Severity: MEDIUM
Fixed Version: 4.1.1, 3.14.2
Link: CVE-2025-64718

Check warning on line 14451 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

lodash: prototype pollution in _.unset and _.omit functions Medium

Package: lodash
Installed Version: 4.17.21
Vulnerability CVE-2025-13465
Severity: MEDIUM
Fixed Version: 4.17.23
Link: CVE-2025-13465

Check warning on line 20160 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

undici: Undici: Denial of Service via excessive decompression steps Medium

Package: undici
Installed Version: 5.29.0
Vulnerability CVE-2026-22036
Severity: MEDIUM
Fixed Version: 7.18.2, 6.23.0
Link: CVE-2026-22036

Check notice on line 4991 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

cookie: cookie accepts cookie name, path, and domain with out of bounds characters Low

Package: cookie
Installed Version: 0.4.2
Vulnerability CVE-2024-47764
Severity: LOW
Fixed Version: 0.7.0
Link: CVE-2024-47764

Check notice on line 19516 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

tmp: tmp Symbolic Link Write Vulnerability Low

Package: tmp
Installed Version: 0.0.33
Vulnerability CVE-2025-54798
Severity: LOW
Fixed Version: 0.2.4
Link: CVE-2025-54798