Skip to content

Fix GHSA-3pwg-f3hj-wp8p#145

Merged
azmkercso merged 1 commit intoaws:1.1from
azmkercso:1.1
Feb 17, 2026
Merged

Fix GHSA-3pwg-f3hj-wp8p#145
azmkercso merged 1 commit intoaws:1.1from
azmkercso:1.1

Conversation

@azmkercso
Copy link
Contributor

Issue

V2104769527

Description of Changes

Added backport manifest json at patches/backported-patches.json
Added a mechanism to security-scan workflow to ignore findings with IDs which have a record in the backport manifest json file
Backported high severity findings from the Code-OSS repository (GHSA-3pwg-f3hj-wp8p / CVE-2026-21523)
CVE-2026-21523 describes multiple findings, of which only one is applicable for a Code Editor use case:

Testing

It is a one-line backport, no additional testing has been performed other than running the GitHub Actions to verify that the scan ignores the backported finding (as expected), and that the backported patch could be properly applied.
Security scan workflow run (on fork): https://github.com/azmkercso/code-editor/actions/runs/22104274205
Build workflow run (on fork): https://github.com/azmkercso/code-editor/actions/runs/22104494664

Screenshots/Videos

N/A

Additional Notes

N/A

Backporting

Yes, a separate PR is being made for all release branches (1.0, 1.1, main)


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

Add patch-backport manifest json
Update security-scan to allow ignoring backported patches
@azmkercso azmkercso requested review from a team as code owners February 17, 2026 15:38
@azmkercso azmkercso merged commit b824094 into aws:1.1 Feb 17, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants