fix(deps): upgrade npm packages for 14 CVE fixes - #1563
Conversation
|
Warning Review limit reachedNext included review available in 50 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe pull request updates the ChangesDependency updates
Estimated code review effort: 2 (Simple) | ~10 minutes Merge Risk: ⚪ Minimal · up to The PR updates dependency versions and resolutions for security fixes without any identified current-head merge-blocking risk; it is merge-ready after normal checks and review. Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Full details: Docstring CoverageExplanation No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.) Full details: Title checkExplanation The title clearly identifies npm dependency upgrades for security fixes, which matches the main change. The stated count of 14 CVE fixes differs from the objective's count of 16, but this does not make the title unrelated or generic. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Upgrades vulnerable dependencies to address 16 CVE security issues: - axios: 1.16.1 → 1.18.0 (CVE-2026-67320, CVE-2026-67314, CVE-2026-67313, CVE-2026-67321) - fast-uri: 3.1.2 → 4.1.3 (CVE-2026-16221) - node-tar: 7.5.6 → 7.5.22 (CVE-2026-73566, CVE-2026-59874, CVE-2026-59873) - js-yaml: 3.14.1 → 5.4.1 (CVE-2026-73643, CVE-2026-59869) - brace-expansion: 5.0.7 → 5.0.9 (CVE-2026-14257, CVE-2026-69152) - ip-address: 10.1.1 → 10.7.0 (CVE-2026-69192) - nanoid: 3.3.11 → 6.0.1 (CVE-2026-73086) - postcss: 8.5.4 → 8.5.26 (CVE-2026-69153) All tests passing (14/14). Fixes: MIG-1993, MIG-1995, MIG-1994, MIG-1992, MIG-1991, MIG-1990, MIG-1983, MIG-1982, MIG-1974, MIG-1970, MIG-1969, MIG-1968, MIG-1967, MIG-1961, MIG-1960, MIG-1959
af2c1ee to
d72e08a
Compare
Summary
Upgrades 6 vulnerable npm dependencies to address 14 CVE security issues.
Security Fixes
Critical Dependencies:
axios: 1.16.1 → 1.18.0
fast-uri: 3.1.2 → 4.1.3
node-tar: 7.5.6 → 7.5.22
js-yaml: 3.14.1 → 5.4.1
Additional Fixes:
brace-expansion: 5.0.7 → 5.0.9
ip-address: 10.1.1 → 10.7.0
Excluded CVEs (Require ESM Migration):
These will be addressed in a separate migration PR.
Testing
Jira Tickets
Fixes: MIG-1993, MIG-1995, MIG-1994, MIG-1992, MIG-1991, MIG-1990, MIG-1983, MIG-1982, MIG-1970, MIG-1969, MIG-1968, MIG-1961, MIG-1960, MIG-1959
🤖 Generated with Claude Code