Skip to content

fix(deps): resolve transitive security advisories - #1412

Open
ZacharyZcR wants to merge 1 commit into
Termix-SSH:mainfrom
ZacharyZcR:fix/dependabot-security-2026-09-08
Open

fix(deps): resolve transitive security advisories#1412
ZacharyZcR wants to merge 1 commit into
Termix-SSH:mainfrom
ZacharyZcR:fix/dependabot-security-2026-09-08

Conversation

@ZacharyZcR

@ZacharyZcR ZacharyZcR commented Sep 7, 2026

Copy link
Copy Markdown
Member

Summary

Pins patched dependency versions for the currently reported security advisories:

  • multer >= 2.3.0
  • sharp >= 0.35.4
  • vitest / @vitest/mocker >= 4.1.11
  • js-yaml@4 >= 4.3.2
  • browserslist >= 4.28.7
  • fast-uri@3 >= 3.1.6
  • @xmldom/xmldom >= 0.8.15
  • qs >= 6.16.0

This keeps the fixes in the existing security PR and rebases it onto the current main.

Validation

  • npm audit: 0 vulnerabilities
  • npm audit --omit=dev: 0 vulnerabilities
  • npm run type-check
  • CI is required again for the updated exact head before merge

@ZacharyZcR ZacharyZcR added dependencies Pull requests that update a dependency file npm security Questions about network security labels Sep 7, 2026
@ZacharyZcR
ZacharyZcR force-pushed the fix/dependabot-security-2026-09-08 branch from 774f717 to 602587d Compare September 9, 2026 02:48
@ZacharyZcR
ZacharyZcR force-pushed the fix/dependabot-security-2026-09-08 branch from 602587d to b83dde5 Compare September 9, 2026 18:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file npm security Questions about network security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant