Skip to content

chore(ci): bump packages#187

Merged
svc-devtoolsbot merged 1 commit intomainfrom
ci/bump-packages
Dec 13, 2023
Merged

chore(ci): bump packages#187
svc-devtoolsbot merged 1 commit intomainfrom
ci/bump-packages

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

  • Bump package versions

@svc-devtoolsbot svc-devtoolsbot merged commit f4bfc6f into main Dec 13, 2023
@svc-devtoolsbot svc-devtoolsbot deleted the ci/bump-packages branch December 13, 2023 17:12
github-actions Bot added a commit that referenced this pull request Apr 29, 2026
…-v6h2-p8h4-qcjw

Add npm overrides to force safe versions of transitive brace-expansion:
- brace-expansion@1 → 1.1.13 (was 1.1.11)
- brace-expansion@2 → 2.0.3 (was 2.0.1/2.0.2)
- brace-expansion@5 → 5.0.5 (was 5.0.2)

Fixes Dependabot alerts #198, #188, #187, #70, #69
CVE-2026-33750 (GHSA-f886-m6hf-6m8v), CVE-2025-5889 (GHSA-v6h2-p8h4-qcjw)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant