Skip to content

chore(deps): bi-weekly security patch of critical vulnerabilities - #878

Merged
ussaama merged 2 commits into
mainfrom
security-patch/vulnerabilities
Jul 28, 2026
Merged

chore(deps): bi-weekly security patch of critical vulnerabilities#878
ussaama merged 2 commits into
mainfrom
security-patch/vulnerabilities

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Scheduled Security Patch

This PR was automatically created by the bi-weekly scheduled security patching job.
It scans for dependency vulnerabilities and upgrades vulnerable packages to safe versions.

Changes:

  • Scanned Python packages with pip-audit and upgraded vulnerable ones using uv.
  • Scanned Node.js packages with pnpm audit and upgraded high/critical ones.
  • Regenerated requirements.lock and lockfiles to match.

🔍 Security Patch Risk Analysis & Breaking Changes

This analysis automatically maps direct dependency upgrades against our codebase to evaluate breaking change risks:

📦 Node.js (Frontend) (echo/frontend/package.json)

Package Upgrade Risk Level Usages in Codebase Guidance
postcss ^8.5.3 ➡️ ^8.5.22 PATCH (Safe) 1 files ✅ Standard bug/security patch. Extremely safe.
react-router ^7.18.0 ➡️ ^7.18.1 PATCH (Safe) 118 files ✅ Standard bug/security patch. Extremely safe.

Please review the upgrades and run tests to ensure no regressions are introduced.

@github-actions github-actions Bot added dependencies Pull requests that update a dependency file security labels Jul 26, 2026
@ussaama
ussaama added this pull request to the merge queue Jul 28, 2026
Merged via the queue into main with commit d8c8c39 Jul 28, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant