Skip to content

fix(security): bump undici, dompurify and brace-expansion lockfile versions - #42

Open
ivanasabi wants to merge 1 commit into
developfrom
fix/dependabot-audit-deps
Open

ivanasabi wants to merge 1 commit into
developfrom
fix/dependabot-audit-deps

Conversation

@ivanasabi

Copy link
Copy Markdown
Contributor

Summary

Closes the 8 open Dependabot alerts by re-resolving both lockfiles with npm audit fix against registry.npmjs.org:

package path before after alerts
undici (transitive of jsdom, dev) /package-lock.json 7.29.0 7.30.0 35, 37, 38, 40, 42, 43
dompurify (dev, via swagger-ui-react) /package-lock.json 3.4.14 3.4.16 45
dompurify (runtime, via swagger-ui-react) example/package-lock.json 3.4.14 3.4.16 44
brace-expansion (dev) /package-lock.json 5.0.9 / 1.1.18 5.0.12 / 1.1.21 (bundled audit)
  • npm audit: 0 vulnerabilities in both lockfiles
  • npm run verify: lint + prettier + 21 vitest tests + build all pass
  • No runtime code changes: only lockfiles (both already pointed at the public npm registry)

…rsions

Resolves the 8 open Dependabot alerts:

- undici 7.29.0 -> 7.30.0 (transitive of jsdom, dev, root lockfile):
  GHSA-3wwx-pv8p-q78v, GHSA-pmjh-fq2x-6v4x, GHSA-r53p-7pc4-xj5r
- dompurify 3.4.14 -> 3.4.16 (root dev + example runtime, both via
  swagger-ui-react): GHSA-p98j-92pf-mc4p
- brace-expansion 1.1.18 -> 1.21, 5.0.9 -> 5.0.12 (root, dev):
  GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p, GHSA-q2hr-2g5m-vwhr

npm audit reports 0 vulnerabilities in both lockfiles; npm run verify
(lint, prettier, 21 vitest tests, build) passes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@ivanasabi
ivanasabi requested a review from a team as a code owner October 5, 2026 13:30
@sonarqubecloud

sonarqubecloud Bot commented Oct 5, 2026

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant