Skip to content

chore(deps): refresh vulnerable transitive dependencies - #100

Merged
anurag629 merged 1 commit into
devfrom
chore/transitive-security
Oct 1, 2026
Merged

anurag629 merged 1 commit into
devfrom
chore/transitive-security

Conversation

@anurag629

Copy link
Copy Markdown
Member

Lockfile-only. Re-resolves the transitive packages with open security alerts to the newest versions their parents already allow: browserslist, defu, fast-uri, fflate, h3, nanoid, picomatch, postcss, svgo, vite, @babel/core and esbuild 0.28. No package.json changes.

Checked on Node 22 like CI: npm ci is clean, 179 tests pass, npm run check has 0 errors and the build completes.

Still open after this, and only fixable with upgrades: astro (needs 7.x), the older esbuild copies pinned by Astro 5 and vite 6, and lodash, which a dependency pins to 4.17.21.

Re-resolves browserslist, defu, fast-uri, fflate, h3, nanoid, picomatch,
postcss, svgo, vite, @babel/core and esbuild 0.28 to the newest versions
their parents allow, which clears their security alerts. No package.json
changes.
@anurag629
anurag629 merged commit c3a6e48 into dev Oct 1, 2026
1 check passed
@anurag629
anurag629 deleted the chore/transitive-security branch October 1, 2026 12:46
anurag629 added a commit that referenced this pull request Oct 1, 2026
Astro 7 and @astrojs/cloudflare 14 (#101), dependency security updates
(#98, #100) and new tests for the template helpers (#90).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant