Skip to content

Fix outstanding security vulns - #38

Merged
yiancar merged 5 commits into
the-via:masterfrom
mini-ninja-64:fix-security-vulns
Mar 23, 2026
Merged

yiancar merged 5 commits into
the-via:masterfrom
mini-ninja-64:fix-security-vulns

Conversation

@mini-ninja-64

@mini-ninja-64 mini-ninja-64 commented Mar 22, 2026 •

Copy link
Copy Markdown
Contributor

This takes care of a few security vulnerabilities, realistically we should switch to something more future-proof like typebox or zod but for now this makes npm audit happy.

  • Replace 'replace' with small custom script that handles the previous changes and some new extra ones required with the upgraded Ajv
  • Add Ajv as an explicit dependency (also upgrade it) instead of the existing peer dependency
  • Upgrade vitest to the latest version still compatible with the deprecated Node 18 the project is still using 😭
  • Move typescript-json-validator to a dev dependency
image

- Add ajv as explicit dependency instead of peer dependency
- Move typescript-json-validator to dev dependency
- Upgrade minimatch
@yiancar
yiancar merged commit 4b79ef2 into the-via:master Mar 23, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants