fix: Security updates #28
+35
−167
Merged
StepSecurity Actions Security / StepSecurity Required Checks
succeeded
Feb 2, 2026 in 1s
StepSecurity Required Checks
Finished StepSecurity Required Checks
- Script Injection Check - Checks for script injection vulnerabilities in the PR
- NPM Compromised Packages Check - Checks for compromised npm package versions in the PR
- NPM Package Cooldown Check - Fails if any package version in the PR was released within the configured cooldown period, helping to avoid brand-new (and potentially unreviewed or malicious) releases
- Pwn Request Vulnerabilities Check - Checks for Pwn Request vulnerabilities in the PR via risky triggers
Details
✅ Script Injection Vulnerabilities Check
No Script Injection vulnerabilities found in this PR.
✅ Pwn Request Vulnerabilities Check
No Pwn Request vulnerabilities found in this PR.
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
✅ NPM Package Cooldown Check
No npm package upgrades to recent releases found in current PR.
The following npm packages are inspected in current PR
| Package Name | Previous Version | Current Version | file | Current Version Release Date |
|---|---|---|---|---|
| axe-core | 4.9.1 | 4.11.1 | package-lock.json | 2026-01-06T18:51:14Z |
| eslint-plugin-jsx-a11y | 6.9.0 | 6.10.2 | package-lock.json | 2024-10-26T04:45:18Z |
| string.prototype.includes | 2.0.0 | 2.0.1 | package-lock.json | 2024-10-15T07:06:28Z |
| aria-query | 5.3.0 | 5.3.2 | package-lock.json | 2024-09-20T19:54:28Z |
| axobject-query | 3.1.1 | 4.1.0 | package-lock.json | 2024-07-15T19:08:33Z |
⏲️ History
Previous invocation results of same check:
✅ Pwn Request Vulnerabilities Check
No Pwn Request vulnerabilities found in this PR.
✅ Script Injection Vulnerabilities Check
No Script Injection vulnerabilities found in this PR.
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
✅ NPM Package Cooldown Check
No npm package upgrades to recent releases found in current PR.
The following npm packages are inspected in current PR
| Package Name | Previous Version | Current Version | file | Current Version Release Date |
|---|---|---|---|---|
| axe-core | 4.9.1 | 4.11.1 | package-lock.json | 2026-01-06T18:51:14Z |
| eslint-plugin-jsx-a11y | 6.9.0 | 6.10.2 | package-lock.json | 2024-10-26T04:45:18Z |
| string.prototype.includes | 2.0.0 | 2.0.1 | package-lock.json | 2024-10-15T07:06:28Z |
| aria-query | 5.3.0 | 5.3.2 | package-lock.json | 2024-09-20T19:54:28Z |
| axobject-query | 3.1.1 | 4.1.0 | package-lock.json | 2024-07-15T19:08:33Z |
⏲️ History
Previous invocation results of same check:
Loading