Skip to content

fix(security): patch pdfjs-dist vulnerability and upgrade CI to Node 20#131

Merged
elainefan331 merged 5 commits into
mainfrom
staging
Jun 1, 2026
Merged

fix(security): patch pdfjs-dist vulnerability and upgrade CI to Node 20#131
elainefan331 merged 5 commits into
mainfrom
staging

Conversation

@elainefan331
Copy link
Copy Markdown
Collaborator

Summary

  • Updated pdfjs-dist to 4.10.38 to patch arbitrary JavaScript execution vulnerability when opening malicious PDFs
  • Updated PDF.js worker CDN URL to match v4 (.mjs format)
  • Upgraded Node.js to 20 across all CI workflows (validate, zodiac deploy, production deploy)

@elainefan331 elainefan331 merged commit 9a57165 into main Jun 1, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant