Skip to content

fix: patch Dependabot security alerts - #58

Merged
John Kennedy (jkennedyvz) merged 1 commit into
mainfrom
fix/dependabot-alerts-2026-07-25
Jul 25, 2026
Merged

fix: patch Dependabot security alerts#58
John Kennedy (jkennedyvz) merged 1 commit into
mainfrom
fix/dependabot-alerts-2026-07-25

Conversation

@jkennedyvz

Copy link
Copy Markdown
Contributor

Summary

  • override PostCSS to 8.5.18
  • override fast-uri to 3.1.4
  • override js-yaml to 4.3.0
  • override brace-expansion to 5.0.8
  • regenerate the npm lockfile

This patches all six currently open Dependabot alerts (#54–#60).

Verification

  • npm ci --ignore-scripts
  • npm run lint (passes with 3 pre-existing formatting warnings)
  • npm run typecheck
  • npm run build
  • npm audit: target packages are clean; 10 unrelated existing findings remain

@jkennedyvz
John Kennedy (jkennedyvz) marked this pull request as ready for review July 25, 2026 20:32
@jkennedyvz
John Kennedy (jkennedyvz) merged commit 5b7c5b3 into main Jul 25, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant