Skip to content

Fix npm dependency security vulnerabilities - #20

Merged
dudetru25 merged 2 commits into
mainfrom
fix/dependabot-undici-vulnerabilities
Aug 4, 2026
Merged

Fix npm dependency security vulnerabilities#20
dudetru25 merged 2 commits into
mainfrom
fix/dependabot-undici-vulnerabilities

Conversation

@dudetru25

@dudetru25 dudetru25 commented Aug 4, 2026

Copy link
Copy Markdown
Member

Summary

  • Update undici to 7.29.0 to resolve the five Dependabot advisories.
  • Update transitive brace-expansion to 5.0.9 and fast-uri to 3.1.5.

Validation

  • npm ci --ignore-scripts --min-release-age=0
  • npm run validate
  • 224 tests passed.
  • npm audit reports 0 vulnerabilities.

The package age-gate exception was limited to these explicitly requested security-hotfix versions.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@dudetru25
dudetru25 merged commit 5cd351b into main Aug 4, 2026
3 checks passed
@dudetru25
dudetru25 deleted the fix/dependabot-undici-vulnerabilities branch August 5, 2026 17:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant