Skip to content

chore(deps): resolve remaining Dependabot security alerts - #143

Open
sadjow wants to merge 1 commit into
mainfrom
fix/dependabot-security-alerts
Open

chore(deps): resolve remaining Dependabot security alerts#143
sadjow wants to merge 1 commit into
mainfrom
fix/dependabot-security-alerts

Conversation

@sadjow

@sadjow sadjow commented Jul 28, 2026

Copy link
Copy Markdown
Member

Summary

  • update both Yarn lockfiles for all 14 currently open GitHub Dependabot alerts
  • patch shell-quote, ws, svgo, postcss, tar, launch-editor, esbuild, and brace-expansion
  • add targeted resolutions where the safe esbuild release and the compatible brace-expansion backport fall outside an upstream transitive range
  • keep legacy and modern brace-expansion consumers on compatible patched APIs instead of forcing one incompatible major across the graph

Validation

  • root frozen Yarn install
  • playground frozen Yarn install
  • ESLint with zero warnings
  • production playground build
  • 22 unit tests

The pull request CI will run the complete integration suite on Node 20 and Node 22.

@sadjow
sadjow requested a review from javiert01 July 28, 2026 17:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant