Skip to content

ci: combine main dependency security bumps - #89

Merged
Qjzn merged 2 commits into
mainfrom
codex/main-deps-audit-20260907-0915
Sep 7, 2026
Merged

ci: combine main dependency security bumps#89
Qjzn merged 2 commits into
mainfrom
codex/main-deps-audit-20260907-0915

Conversation

@Qjzn

@Qjzn Qjzn commented Sep 7, 2026

Copy link
Copy Markdown
Owner

This combines the two main-target dependency security updates that are blocked when checked independently:

Reason:

  • Each original PR leaves one remaining moderate audit finding, so its individual build check fails.
  • The combined candidate resolves the audit set together.

Local verification on Windows, isolated worktree from origin/main:

  • npm 10.9.8 via temporary npm tarball
  • npm ci: 0 vulnerabilities
  • npm run verify:dependency-security: passed, 0 vulnerabilities across 437 dependencies
  • npm run build:frontend: passed

dependabot Bot added 2 commits September 7, 2026 09:11
Bumps [@xmldom/xmldom](https://github.com/xmldom/xmldom) from 0.8.13 to 0.8.15.
- [Release notes](https://github.com/xmldom/xmldom/releases)
- [Changelog](https://github.com/xmldom/xmldom/blob/master/CHANGELOG.md)
- [Commits](xmldom/xmldom@0.8.13...0.8.15)

---
updated-dependencies:
- dependency-name: "@xmldom/xmldom"
  dependency-version: 0.8.15
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [qs](https://github.com/ljharb/qs) from 6.15.3 to 6.16.0.
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.15.3...v6.16.0)

---
updated-dependencies:
- dependency-name: qs
  dependency-version: 6.16.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@Qjzn
Qjzn merged commit f0759e5 into main Sep 7, 2026
4 checks passed
@Qjzn
Qjzn deleted the codex/main-deps-audit-20260907-0915 branch September 7, 2026 01:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant