Skip to content

fix(deps): resolve 4 dependabot security alerts - #17

Merged
Faustze merged 1 commit into
mainfrom
fix/dependabot-security-alerts
Jul 23, 2026
Merged

fix(deps): resolve 4 dependabot security alerts#17
Faustze merged 1 commit into
mainfrom
fix/dependabot-security-alerts

Conversation

@Faustze

@Faustze Faustze commented Jul 23, 2026

Copy link
Copy Markdown
Owner

Bumps three transitive dependencies within their already-declared semver ranges (no overrides needed):

  • immutable 5.1.6 -> 5.1.9 (hash-collision DoS, 32-bit trie overflow DoS)
  • brace-expansion 5.0.6 -> 5.0.8 (exponential-time expansion DoS)
  • brace-expansion 1.1.15 -> 1.1.16 (same, nested under serve-handler)

Bumps three transitive dependencies within their already-declared
semver ranges (no overrides needed):
- immutable 5.1.6 -> 5.1.9 (hash-collision DoS, 32-bit trie overflow DoS)
- brace-expansion 5.0.6 -> 5.0.8 (exponential-time expansion DoS)
- brace-expansion 1.1.15 -> 1.1.16 (same, nested under serve-handler)
@coderabbitai

coderabbitai Bot commented Jul 23, 2026

Copy link
Copy Markdown

Important

Review skipped

Review was skipped due to path filters

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json

CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including **/dist/** will override the default block on the dist directory, by removing the pattern from both the lists.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 43c3085b-d8df-4e33-9e54-7fb9ab3f927e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/dependabot-security-alerts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Faustze
Faustze merged commit 65d3b86 into main Jul 23, 2026
7 checks passed
@Faustze
Faustze deleted the fix/dependabot-security-alerts branch July 24, 2026 12:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant