Skip to content

[Chore] Consolidate dependency security bumps - #84

Merged
manfredcml merged 1 commit into
mainfrom
chore/security-dep-bumps
Jul 30, 2026
Merged

[Chore] Consolidate dependency security bumps#84
manfredcml merged 1 commit into
mainfrom
chore/security-dep-bumps

Conversation

@manfredcml

@manfredcml manfredcml commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

What does this PR do?

Consolidates the open Dependabot dependency bumps. Also clears the one open advisory that had no Dependabot PR.

Closes #81, #80, #77, #76, #75.

Changes:

  • russh: 0.61.2 to 0.62.4, pulling ssh-key rc.10 to rc.11 and russh-cryptovec 0.61 to 0.62. No source changes needed; the API used by the SSH tunnel is unchanged.
  • postcss: 8.5.25 in both frontend and docs.
  • astro: ^6.3.3 to ^7.1.6, the ancestor bump required to carry sharp 0.34.5 to 0.35.3.
  • svgo: 4.0.1 to 4.0.2.
  • brace-expansion: 5.0.8 in frontend, clearing GHSA-mh99-v99m-4gvg. No Dependabot PR was open for this one.

Checklist

  • I opened an issue first for non-trivial changes, or this is a small fix.
  • Tests added/updated for my change.
  • I license my contribution under the MIT License, per CONTRIBUTING.md. I confirm this is my original work, or that I have the right to submit it.

Bumps the dependencies flagged by Dependabot in PRs #81, #80, #77, #76,
and #75 into one change, plus the open brace-expansion advisory.

Changes:
- russh: 0.61.2 to 0.62.4 (pulls ssh-key rc.10 to rc.11, russh-cryptovec 0.61 to 0.62)
- postcss: 8.5.25 in both frontend and docs
- astro: ^6.3.3 to ^7.1.6, carrying sharp 0.34.5 to 0.35.3
- svgo: 4.0.1 to 4.0.2
- brace-expansion: 5.0.8 in frontend, clearing GHSA-mh99-v99m-4gvg
@manfredcml
manfredcml merged commit 0f6baf5 into main Jul 30, 2026
6 checks passed
@manfredcml
manfredcml deleted the chore/security-dep-bumps branch July 30, 2026 17:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant