Skip to content

fix(deps): close the remaining security advisories - #222

Merged
oleksandr-nc merged 1 commit into
mainfrom
chore/security-updates
Jul 31, 2026
Merged

fix(deps): close the remaining security advisories#222
oleksandr-nc merged 1 commit into
mainfrom
chore/security-updates

Conversation

@oleksandr-nc

Copy link
Copy Markdown
Contributor

Applies the updates the Dependabot PRs could not land themselves. Several of them closed with "no longer updatable" without the bump ever reaching main.

馃 AI (if applicable)

  • The content of this PR was partly or fully generated using AI

Applies the updates the Dependabot PRs could not land themselves. Several of
them closed with "no longer updatable" without the bump ever reaching main,
and vite needed 7.3.5 while the PR only offered 7.3.2.

vite 7.2.2 -> 7.3.6 (high, medium), js-yaml 4.1.1 -> 4.3.0 (high, medium),
brace-expansion -> 1.1.18/2.1.4/5.0.9 (high), @babel/core 7.28.x -> 7.29.7 (low),
picomatch 2.3.1 -> 2.3.2, esbuild, and fast-xml-parser 5.10.1 with webdav 5.10.0.

The fast-xml-parser and webdav updates are the useful half of #219. That PR also
raised @nextcloud/eslint-config to 9 and eslint to 10, which needs a flat config
this app does not have, so it fails the build outright. eslint stays on 8.57.1
here and the migration is left as its own piece of work.

Signed-off-by: Oleksander Piskun <oleksandr2088@icloud.com>
@oleksandr-nc
oleksandr-nc requested a review from kyteinsky as a code owner July 31, 2026 12:19
@oleksandr-nc
oleksandr-nc merged commit ceeea7a into main Jul 31, 2026
28 checks passed
@oleksandr-nc
oleksandr-nc deleted the chore/security-updates branch July 31, 2026 12:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant