Revert "chore: npm audit fix" - #333676
Approved by 2/2 collaborators
PR classified as team-member.
2b82959 is signed by GitHub, not by a trusted team member. GitHub adds its own "Verified" signature to commits it creates on your behalf — e.g. edits made in the github.com web editor, suggestions applied from a review, or commits made via Codespaces or the GitHub API. That signature only proves GitHub made the commit, not that a trusted team member authored it, so it does not earn the signing credit. To get the credit, create the commit locally, and sign it with a trusted key.)
Tip: to earn the credit (−1 approval), the head commit must be signed by you with one of your own keys listed in security/trusted-signing-keys.csv. A "Verified" badge that GitHub adds to commits it creates on your behalf — web-editor edits, applied suggestions, Codespaces, API commits — does not count.
✅ Collaborator approvals: 2/2 (vritant24, bhavyaus).
✅ No newly added runnable binary files.
✅ Engineering system changes are allowed.
build/agent-sdk/agents/claude/package-lock.json
The PR author is a current VS Code team member.