Skip to content

Fix esbuild security advisory#29

Merged
swilla merged 1 commit into
mainfrom
chore/fix-esbuild-advisory
Jun 14, 2026
Merged

Fix esbuild security advisory#29
swilla merged 1 commit into
mainfrom
chore/fix-esbuild-advisory

Conversation

@swilla

@swilla swilla commented Jun 14, 2026

Copy link
Copy Markdown
Member

Summary

  • pin esbuild to 0.28.1, the patched release for GHSA-gv7w-rqvm-qjhr
  • track package-lock.json so Dependabot has a supported npm manifest/lockfile to update going forward

Verification

  • npm audit
  • npm run build
  • composer validate --strict --no-check-lock
  • composer test

@swilla swilla merged commit 42f3b77 into main Jun 14, 2026
1 check passed
@swilla swilla deleted the chore/fix-esbuild-advisory branch June 14, 2026 18:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant