Skip to content

DEVDOCS-17857#26

Merged
paigesrossi merged 2 commits intomainfrom
security-patch
Mar 6, 2026
Merged

DEVDOCS-17857#26
paigesrossi merged 2 commits intomainfrom
security-patch

Conversation

@raileendr
Copy link
Copy Markdown
Contributor

No description provided.

@raileendr raileendr changed the title bump-deps DEVDOCS-17857 Feb 26, 2026
@InbarGazit InbarGazit requested a review from Copilot February 26, 2026 18:28
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates two direct dependencies in the ClientApp package: ajv from 8.17.1 to 8.18.0 (minor version bump) and axios from 1.13.2 to 1.13.5 (patch version bump). The changes include updates to transitive dependencies, particularly follow-redirects (1.15.6 → 1.15.11) and form-data (4.0.4 → 4.0.5), which likely address security vulnerabilities. The yarn.lock file also shows extensive reorganization with many entries being reordered alphabetically.

Changes:

  • Updated ajv to 8.18.0 for improved JSON schema validation
  • Updated axios to 1.13.5 along with its dependencies to address potential security issues
  • Reorganized yarn.lock file entries (alphabetical reordering)

Reviewed changes

Copilot reviewed 1 out of 3 changed files in this pull request and generated no comments.

File Description
DocuSign.Workspaces/DocuSign.Workspaces/ClientApp/package.json Updated direct dependencies: ajv (8.17.1 → 8.18.0) and axios (1.13.2 → 1.13.5)
DocuSign.Workspaces/DocuSign.Workspaces/ClientApp/yarn.lock Regenerated lockfile with updated dependency versions and extensive reorganization; includes transitive dependency updates

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@paigesrossi paigesrossi merged commit 929bc2d into main Mar 6, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants