Skip to content

chore(ci): bump packages#262

Merged
svc-devtoolsbot merged 1 commit into
mainfrom
ci/bump-packages
Mar 11, 2024
Merged

chore(ci): bump packages#262
svc-devtoolsbot merged 1 commit into
mainfrom
ci/bump-packages

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

  • Bump package versions

@svc-devtoolsbot svc-devtoolsbot merged commit 98254a4 into main Mar 11, 2024
@svc-devtoolsbot svc-devtoolsbot deleted the ci/bump-packages branch March 11, 2024 16:36
github-actions Bot added a commit that referenced this pull request May 19, 2026
Adds npm overrides to pin brace-expansion to 5.0.6 across all
transitive dependencies. Also patches the package-lock.json entry for
packages/sbom-tools/node_modules/brace-expansion which was not
automatically updated due to npm workspace override behaviour.

Fixes CVE-2026-45149 / GHSA-jxxr-4gwj-5jf2 (Dependabot alert #262).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant