fix: update nitropack to resolve CVE-2026-44372 and CVE-2026-44373#82
Conversation
Co-Authored-By: Oz <oz-agent@warp.dev>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
I'm starting a first review of this pull request. You can view the conversation on Warp. I completed the review and no human review was requested for this pull request. Comment Powered by Oz |
There was a problem hiding this comment.
Overview
This PR updates the transitive nitropack lockfile entry from 2.13.3 to 2.13.4, with corresponding nested dependency resolution changes in package-lock.json, to address the referenced Dependabot CVEs.
Concerns
No material correctness, spec-alignment, or security concerns were found in the annotated diff. The provided spec context indicates no approved repository spec exists for this PR.
Verdict
Found: 0 critical, 0 important, 0 suggestions
Approve
Comment /oz-review on this pull request to retrigger a review (up to 3 times on the same pull request).
Powered by Oz
Summary
nitropackfrom2.13.3to2.13.4inpackage-lock.json.Security alerts
Advisories
Verification
npm auditno longer reportsnitropack.npm run buildpassed.npm run typecheckpassed with 0 errors and existing hints only.npm run lintcould not run in this sandbox becausetrunkis not installed.Conversation: https://staging.warp.dev/conversation/afca70f9-a90b-442c-80fd-2d073799a893
Run: https://oz.staging.warp.dev/runs/019e3184-3c43-7402-ad9b-0a6cc3a2ba17
This PR was generated with Oz.