Skip to content

[Infrastructure] Update vulnerable npm dependencies - #68233

Merged
wtgodbe merged 1 commit into
dotnet:mainfrom
wtgodbe:infrastructure/fix-production-npm-cg-main-2026-08-05
Aug 5, 2026
Merged

[Infrastructure] Update vulnerable npm dependencies#68233
wtgodbe merged 1 commit into
dotnet:mainfrom
wtgodbe:infrastructure/fix-production-npm-cg-main-2026-08-05

Conversation

@wtgodbe

@wtgodbe wtgodbe commented Aug 5, 2026

Copy link
Copy Markdown
Member

Updates brace-expansion from 1.1.16 to 1.1.17 throughout the root npm lockfile to resolve CVE-2026-14257.

The active low-severity @babel/core alert is already addressed by @babel/core 7.29.7 in the latest main lockfile. The medium-severity keyv alert remains because its remediation requires moving from 4.x to 5.5.3, and this update intentionally avoids major-version bumps for Medium and Low alerts.

The updated package was ingested through the dotnet-public-npm Azure Artifacts feed.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings August 5, 2026 16:15

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

@wtgodbe
wtgodbe merged commit 5b85db2 into dotnet:main Aug 5, 2026
28 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants