Skip to content

Conversation

@CreatorHead
Copy link
Collaborator

Fix For:


  • Upgrade @octokit/plugin-retry from 4.1.3 to 8.0.3
  • Upgrade @octokit/plugin-throttling from 5.0.1 to 11.0.3
  • Replace deprecated onAbuseLimit with onSecondaryRateLimit handler
  • Fixes GHSA-rmvr-2pp2-xj38 (@octokit/request ReDoS)
  • Fixes GHSA-xx4v-prfh-6cgc (@octokit/request-error ReDoS)
  • All tests passing, zero production vulnerabilities

PCI review checklist

  • I have documented a clear reason for, and description of, the change I am making.

  • If applicable, I've documented a plan to revert these changes if they require more than reverting the pull request.

  • If applicable, I've documented the impact of any changes to security controls.

    Examples of changes to security controls include using new access control methods, adding or removing logging pipelines, etc.

- Upgrade @octokit/plugin-retry from 4.1.3 to 8.0.3
- Upgrade @octokit/plugin-throttling from 5.0.1 to 11.0.3
- Replace deprecated onAbuseLimit with onSecondaryRateLimit handler
- Fixes GHSA-rmvr-2pp2-xj38 (@octokit/request ReDoS)
- Fixes GHSA-xx4v-prfh-6cgc (@octokit/request-error ReDoS)
- All tests passing, zero production vulnerabilities
@CreatorHead CreatorHead requested a review from a team as a code owner January 8, 2026 07:53
@CreatorHead CreatorHead merged commit a04637e into main Jan 8, 2026
6 checks passed
@CreatorHead CreatorHead deleted the fix/octokit-redos-vulnerabilities branch January 8, 2026 09:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants