Skip to content

Fix esbuild security advisory#10

Merged
swilla merged 1 commit into
mainfrom
chore/fix-esbuild-advisory
Jun 14, 2026
Merged

Fix esbuild security advisory#10
swilla merged 1 commit into
mainfrom
chore/fix-esbuild-advisory

Conversation

@swilla

@swilla swilla commented Jun 14, 2026

Copy link
Copy Markdown
Member

Summary

  • pin esbuild to 0.28.1, the patched release for GHSA-gv7w-rqvm-qjhr
  • track package-lock.json so Dependabot has a supported npm manifest/lockfile to update going forward
  • refresh the lockfile so npm audit is clean, including the transitive markdown-it advisory

Verification

  • npm audit
  • composer validate --strict --no-check-lock
  • composer test

@swilla swilla merged commit eb4136e into main Jun 14, 2026
2 checks passed
@swilla swilla deleted the chore/fix-esbuild-advisory branch June 14, 2026 18:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant