bcgov / bcgov/alcs

Recurring task to address security vulnerabilities

Open
#3,140 0 comments 0 reactions 0 assignees View on GitHub
Task
Dominant language
TypeScript
Stars
10
Forks
0
Avg merge
20h 8m
Merged PRs (30d)
30

Description

**Describe the task**
Patch critical and high severity security vulnerabilities identified by Dependabot, Trivy, and Advanced Cluster Security (ACS).

**Acceptance Criteria**
- [ ] if possible, can we just do this to Test branch so we don't have to regression test features added to dev?
- [ ] apply dependabot PRs
- [ ] upgrade packages as needed
- [ ] deploy to Test as required
- [ ] iteratively run Trivy and ACS to check for outstanding issues

**Additional context**
- Did we get to ACS in Fall 2026 round?

Confirm this task meets our team [**Definition of Ready (DoR)**](https://www.figma.com/board/XmNkN600aAVWFCBmSDdt10/Team-Documents?node-id=1-2&t=Xjd6nHZZ7YlnoOrD-4) before moving to the **Next Sprint** column.

Confirm this task meets our team [**Definition of Done (DoD)**](https://www.figma.com/board/XmNkN600aAVWFCBmSDdt10/Team-Documents?node-id=3-21&t=Xjd6nHZZ7YlnoOrD-4) before moving to the **Done** column.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the outstanding Dependabot, Trivy, and Advanced Cluster Security findings and the current Test branch deployment process. Apply the required dependency upgrades, deploy to Test as needed, and rerun Trivy and ACS until critical and high severity vulnerabilities are addressed; regression impact and the Fall 2026 ACS status remain to be clarified.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
devops, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
28/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.