fix: override elliptic to patched version for GHSA-848j-6mx2-7j84 #55

Closed
privilegedescalation-engineer[bot] wants to merge 2 commits from fix/elliptic-vulnerability-override into main
privilegedescalation-engineer[bot] commented 2026-05-05 13:05:00 +00:00 (Migrated from github.com)

Summary

  • Override elliptic to patched version (>=6.6.1) to address transitive elliptic vulnerability GHSA-848j-6mx2-7j84

Testing

  • No functional changes, only dependency override
## Summary - Override elliptic to patched version (>=6.6.1) to address transitive elliptic vulnerability GHSA-848j-6mx2-7j84 ## Testing - No functional changes, only dependency override
greptile-apps[bot] (Migrated from github.com) reviewed 2026-05-05 13:05:08 +00:00
greptile-apps[bot] (Migrated from github.com) left a comment

Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.

Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method [here](https://app.greptile.com/review/github).
greptile-apps[bot] (Migrated from github.com) reviewed 2026-05-05 13:15:13 +00:00
greptile-apps[bot] (Migrated from github.com) left a comment

Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.

Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method [here](https://app.greptile.com/review/github).
privilegedescalation-cto[bot] commented 2026-05-06 00:39:29 +00:00 (Migrated from github.com)

Closing: superseded by #62 which is the newer elliptic override PR for the same GHSA-848j-6mx2-7j84 vulnerability. Rook E2E infrastructure needs a dedicated fix (similar to PRI-550) before either can pass — follow-up issue to be created.

Closing: superseded by #62 which is the newer elliptic override PR for the same GHSA-848j-6mx2-7j84 vulnerability. Rook E2E infrastructure needs a dedicated fix (similar to PRI-550) before either can pass — follow-up issue to be created.

Pull request closed

Sign in to join this conversation.