Skip to content

swap vendored leaflet with npm leaflet #5695

Description

@rshewitt

User Story

In order to not be on the hook for security updates and allow auto-updates to occur, datagov wants to swap our vendored leaflet instance with the npm version

Acceptance Criteria

[ACs should be clearly demoable/verifiable whenever possible. Try specifying them using BDD.]

  • GIVEN we don't want to be on the hook for security updates for leaflet
    AND we want dependabot to do its job
    WHEN the vendored version of leaflet is removed
    THEN its derived from npm instead
    AND CSP policies are updated so no change in functionality occurs

Background

try to avoid allowing entire package registries in our CSP. we vendored leaflet to avoid having to do that. however, we haven't been notified that we've violated some security policy so maybe using registries is okay?

Security Considerations (required)

[Any security concerns that might be implicated in the change. "None" is OK, just be explicit here!]

Sketch

[Notes or a checklist reflecting our understanding of the selected approach]

Activity

  1. moved this to Queue for Next Sprint in data.gov team boardon Feb 19, 2026
  2. neilmb commented on Feb 20, 2026

    @neilmb

    We also added some leaflet image files in GSA/datagov-catalog#174. When we use npm to package leaflet, the images will likely get installed elsewhere and we can remove the ones we added manually.

  3. FuhuXia commented on Feb 20, 2026

    @FuhuXia
    Member

    After leaflet npm'ed, we need to come back and briefly check that the marker image is not broken. it seems to be a known leaflet issue.

  4. moved this from Queue for Next Sprint to 📥 Queue in data.gov team boardon Feb 25, 2026
  5. moved this from 📥 Queue to Next Up in data.gov team boardon Apr 9, 2026
  6. SueValente commented on Apr 23, 2026

    @SueValente
    Contributor

    this is working now and have another 6 months before we need to address this

  7. moved this from Next Up to 📥 Queue in data.gov team boardon Apr 23, 2026
  8. moved this from 📥 Queue to No status in data.gov team boardon Apr 23, 2026
  9. added this to the 2026 07 milestone on Jun 24, 2026
  10. added
    Security - complianceRelating to security compliance or documentation
    O&MOperations and maintenance tasks for the Data.gov platform
    on Jun 24, 2026
  11. moved this from O&M Specific Backlog to 📟 Sprint Backlog (Top Priority) in data.gov team boardon Jul 15, 2026
  12. self-assigned this
    on Jul 24, 2026
  13. moved this from 📟 Sprint Backlog (Top Priority) to 🏗 In Progress in data.gov team boardon Jul 28, 2026
  14. moved this from 🏗 In Progress to 👀 Needs Review in data.gov team boardon Jul 29, 2026
  15. moved this from 👀 Needs Review to ✔ Done in data.gov team boardon Jul 29, 2026
  16. moved this from ✔ Done to 🗄 Closed in data.gov team boardon Aug 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

O&MOperations and maintenance tasks for the Data.gov platformSecurity - complianceRelating to security compliance or documentation

Type

No type

Projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions