Skip to content

fix(security): update vulnerable dependencies - #31

Merged
smiggleworth merged 1 commit into
mainfrom
fix/dependency-alerts
Jul 28, 2026
Merged

fix(security): update vulnerable dependencies#31
smiggleworth merged 1 commit into
mainfrom
fix/dependency-alerts

Conversation

@smiggleworth

Copy link
Copy Markdown
Contributor

Summary

  • update brace-expansion to the patched 5.0.8 release
  • update direct js-yaml to the patched 5.2.2 release

Validation

  • npm ci --ignore-scripts
  • npm audit --audit-level=high (0 vulnerabilities)
  • npm run check
  • npm run test:templates

Closes the two open high-severity Dependabot alerts.

Copilot AI review requested due to automatic review settings July 28, 2026 15:44

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@smiggleworth
smiggleworth merged commit 5df6424 into main Jul 28, 2026
8 checks passed
@smiggleworth
smiggleworth deleted the fix/dependency-alerts branch July 28, 2026 15:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants