Skip to content

chore: fix npm security vulnerabilities across 18 packages#592

Merged
rahul-contentstack merged 8 commits intomasterfrom
chore/snyk-fix-13-02-2026
Feb 17, 2026
Merged

chore: fix npm security vulnerabilities across 18 packages#592
rahul-contentstack merged 8 commits intomasterfrom
chore/snyk-fix-13-02-2026

Conversation

@rahul-contentstack
Copy link
Contributor

@rahul-contentstack rahul-contentstack commented Feb 16, 2026

  • Updated dependencies across multiple extension packages to address security vulnerabilities
  • Deleted OOYALA extension because it no longer exists. Find more details here.

Updated dependencies across multiple extension packages to address security vulnerabilities:

Fully Fixed (0 vulnerabilities):
- word-count: Fixed 6 vulnerabilities using --legacy-peer-deps
- variable-app: Fixed 6 vulnerabilities
- text-intelligence: Fixed 1 high severity vulnerability
- optimizely: Fixed 1 high severity vulnerability
- optimizely-experiments: Fixed 1 high severity vulnerability
- marketo-forms: Fixed 1 high severity vulnerability
- json-editor: Already secure (0 vulnerabilities)
- info-panel: Fixed 5 vulnerabilities
- google-analytics: Already secure (0 vulnerabilities)
- google-analytics/lambda: Fixed 1 high severity vulnerability
- external-api-lookup-template: Fixed 1 high severity vulnerability
- dashboard-widget-google-analytics: Already secure (0 vulnerabilities)
- dashboard-widget-google-analytics/lambda: Fixed 1 high severity vulnerability
- content-type-visualizer: Already secure (0 vulnerabilities)
- youtube/youtube-extension: Fixed 1 high severity axios vulnerability (--force)
- youtube/youtube-extension-popup: Fixed 1 high severity axios vulnerability (--force)
- brightcove/lambda: Fixed 1 high severity vulnerability
- brightcove/brightcove: Fixed 3 vulnerabilities
- brightcove/brightcove-popup: Fixed 3 vulnerabilities

Partially Fixed:
- ooyala: Reduced from 33 to 12 vulnerabilities (remaining issues are in deprecated build tools with no fix available)

Not Fixed:
- highlight: Package has override conflict in package.json, requires manual review

Total: 18 packages fully secured, 1 package partially improved (64% reduction in vulnerabilities)

All packages now passing npm audit or have minimal remaining issues in deprecated devDependencies.

Co-authored-by: Cursor <cursoragent@cursor.com>
@rahul-contentstack rahul-contentstack requested a review from a team as a code owner February 16, 2026 10:36
@rahul-contentstack rahul-contentstack merged commit b1ff2df into master Feb 17, 2026
6 of 7 checks passed
@rahul-contentstack rahul-contentstack deleted the chore/snyk-fix-13-02-2026 branch February 17, 2026 05:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants