Skip to content

chore(deps): bump npm dependencies to resolve Dependabot alerts#148

Merged
StefanSteiner merged 1 commit into
tableau:mainfrom
StefanSteiner:fix/dependabot-npm-alerts
Jun 16, 2026
Merged

chore(deps): bump npm dependencies to resolve Dependabot alerts#148
StefanSteiner merged 1 commit into
tableau:mainfrom
StefanSteiner:fix/dependabot-npm-alerts

Conversation

@StefanSteiner

Copy link
Copy Markdown
Contributor

Summary

Resolves 5 open Dependabot alerts by bumping npm dependencies:

Dependency changes in hyper-explorer/package.json

Package Before After
vite ^7.3.1 ^8.0.16
@vitejs/plugin-react ^4.3.0 ^5.2.0
tsx ^4.21.0 ^4.22.4

The remaining Dependabot alert (#1, thrift in Cargo.lock) is a false positive for Rust — already accepted in deny.toml.

Test plan

  • CI passes (node-bindings job builds hyperdb-api-node successfully)
  • npm audit shows 0 vulnerabilities in both directories
  • hyper-explorer dev server starts without errors (npm run dev)

- hyperdb-api-node: esbuild 0.28.0 → 0.28.1 (GHSA-gv7w-rqvm-qjhr,
  GHSA-g7r4-m6w7-qqqr)
- hyper-explorer: vite 7.3.5 → 8.0.16, @vitejs/plugin-react 4.3.0 →
  5.2.0, tsx 4.21.0 → 4.22.4 — pulls in esbuild 0.28.1 and
  @babel/core 7.29.7 (GHSA-4x5r-pxfx-6jf8)
@StefanSteiner StefanSteiner merged commit f37c2d7 into tableau:main Jun 16, 2026
21 of 22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant