Skip to content

Update vulnerable transitive dependencies - #506

Merged
anumol-baby merged 1 commit into
mainfrom
anu/fix-brace-expansion-vulnerability
Sep 4, 2026
Merged

Update vulnerable transitive dependencies#506
anumol-baby merged 1 commit into
mainfrom
anu/fix-brace-expansion-vulnerability

Conversation

@anumol-baby

Copy link
Copy Markdown
Contributor

Updates the generated npm lockfile to use patched transitive dependency versions:

  • body-parser 1.20.6
  • brace-expansion 1.1.18 and 2.1.4

Direct dependencies remain unchanged.

Validation:

  • npm ci
  • Application smoke test returns HTTP 200

Copilot AI balanced review requested due to automatic review settings September 3, 2026 09:32

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@anumol-baby
anumol-baby merged commit 32c5b65 into main Sep 4, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants