Skip to content

fix: patches undici and serialize-javascript vulnerabilities#3596

Merged
eablack merged 2 commits intomainfrom
tl/vulnerability-patches
Mar 17, 2026
Merged

fix: patches undici and serialize-javascript vulnerabilities#3596
eablack merged 2 commits intomainfrom
tl/vulnerability-patches

Conversation

@tlowrimore-heroku
Copy link
Contributor

Summary

This PR updates dependencies to address 4 high severity vulnerabilities in the undici and serialize-javascript packages.

Type of Change

Breaking Changes (major semver update)

  • Add a ! after your change type to denote a change that breaks current behavior

Feature Additions (minor semver update)

  • feat: Introduces a new feature to the codebase

Patch Updates (patch semver update)

  • fix: Bug fix
  • deps: Dependency upgrade
  • revert: Revert a previous commit
  • chore: Change that does not affect production code
  • refactor: Refactoring existing code without changing behavior
  • test: Add/update/remove tests

Testing

Notes:
Passing CI tests suffice

Related Issues

Dependabot Security Issues: #252, #258, #256, and #254

@eablack eablack merged commit 003d4aa into main Mar 17, 2026
17 checks passed
@eablack eablack deleted the tl/vulnerability-patches branch March 17, 2026 16:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants