Skip to content

chore(ci): bump packages#173

Merged
svc-devtoolsbot merged 1 commit intomainfrom
ci/bump-packages
Sep 26, 2023
Merged

chore(ci): bump packages#173
svc-devtoolsbot merged 1 commit intomainfrom
ci/bump-packages

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

  • Bump package versions

@svc-devtoolsbot svc-devtoolsbot merged commit fcfa7be into main Sep 26, 2023
@svc-devtoolsbot svc-devtoolsbot deleted the ci/bump-packages branch September 26, 2023 11:49
github-actions Bot added a commit that referenced this pull request Apr 19, 2026
Addresses two Dependabot alerts:
- Alert #173: GHSA-5c6j-r48x-rmvq (RCE via RegExp.flags/Date.toISOString, high severity)
- Alert #199: GHSA-qj8w-gfj5-8c6v / CVE-2026-34043 (DoS via CPU exhaustion, medium severity)

Both mocha@^8.4.0 and terser-webpack-plugin@^5.3.x ship serialize-javascript
6.x, and neither has released a version shipping >=7.0.5. Adding an npm
`overrides` entry forces all transitive instances to resolve to 7.0.5+.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant