Skip to content

Fix critical and high npm vulnerabilities #904

Merged
bigdaz merged 2 commits intomainfrom
vulnerabilities
Mar 23, 2026
Merged

Fix critical and high npm vulnerabilities #904
bigdaz merged 2 commits intomainfrom
vulnerabilities

Conversation

@bigdaz
Copy link
Copy Markdown
Member

@bigdaz bigdaz commented Mar 23, 2026

Update transitive dependencies to resolve 4 security vulnerabilities:

  • fast-xml-parser 5.2.0 → 5.5.8 (critical: DoS, entity expansion, stack overflow)
  • flatted 3.3.3 → 3.4.2 (high: recursion DoS, prototype pollution)
  • minimatch 3.1.2/5.1.6/9.0.5 → 3.1.5/5.1.9/9.0.9 (high: ReDoS)
  • undici 6.23.0/7.21.0 → 6.24.1/7.24.5 (high: WebSocket overflow, HTTP smuggling)

Co-Authored-By: Claude Opus 4.6 (1M context) noreply@anthropic.com

bigdaz and others added 2 commits March 23, 2026 10:19
Update transitive dependencies to resolve 4 security vulnerabilities:
- fast-xml-parser 5.2.0 → 5.5.8 (critical: DoS, entity expansion, stack overflow)
- flatted 3.3.3 → 3.4.2 (high: recursion DoS, prototype pollution)
- minimatch 3.1.2/5.1.6/9.0.5 → 3.1.5/5.1.9/9.0.9 (high: ReDoS)
- undici 6.23.0/7.21.0 → 6.24.1/7.24.5 (high: WebSocket overflow, HTTP smuggling)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@bigdaz bigdaz merged commit 8bfa39f into main Mar 23, 2026
124 of 126 checks passed
@bigdaz bigdaz deleted the vulnerabilities branch March 23, 2026 17:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant