Skip to content

fix: update liquidjs and uuid to patch CVEs#4954

Merged
Yndira-E merged 1 commit into
mainfrom
fix/security-deps-liquidjs-uuid
May 6, 2026
Merged

fix: update liquidjs and uuid to patch CVEs#4954
Yndira-E merged 1 commit into
mainfrom
fix/security-deps-liquidjs-uuid

Conversation

@Yndira-E
Copy link
Copy Markdown
Contributor

@Yndira-E Yndira-E commented May 6, 2026

Summary

  • liquidjs 10.25.5 → 10.25.7: fixes CVE-2026-41311 (HIGH) — Denial of Service via circular block reference in layout
  • uuid 11.1.0 → 11.1.1: fixes CVE-2026-41907 (MEDIUM)

Both were flagged by Trivy in #4953.

Test plan

  • Trivy check passes on this PR
  • Site builds without errors (npm run build)

🤖 Generated with Claude Code

- liquidjs 10.25.5 → 10.25.7 (CVE-2026-41311, HIGH: DoS via circular block reference)
- uuid 11.1.0 → 11.1.1 (CVE-2026-41907, MEDIUM)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@Yndira-E Yndira-E requested a review from a team as a code owner May 6, 2026 14:27
@netlify
Copy link
Copy Markdown

netlify Bot commented May 6, 2026

Deploy Preview for flowforge-website ready!

Name Link
🔨 Latest commit 48ad673
🔍 Latest deploy log https://app.netlify.com/projects/flowforge-website/deploys/69fb4fc44da0150008f3178d
😎 Deploy Preview https://deploy-preview-4954--flowforge-website.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
Lighthouse
Lighthouse
1 paths audited
Performance: 91 (🟢 up 1 from production)
Accessibility: 86 (no change from production)
Best Practices: 92 (no change from production)
SEO: 91 (no change from production)
PWA: -
View the detailed breakdown and full score reports

To edit notification comments on pull requests, go to your Netlify project configuration.

@Yndira-E Yndira-E merged commit b18a2bf into main May 6, 2026
7 checks passed
@Yndira-E Yndira-E deleted the fix/security-deps-liquidjs-uuid branch May 6, 2026 14:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant