Skip to content

Build: resolve Dependabot security alerts - #729

Open
leonardo-costa-IBM wants to merge 1 commit into
masterfrom
fix/remaining-security-alerts-725
Open

leonardo-costa-IBM wants to merge 1 commit into
masterfrom
fix/remaining-security-alerts-725

Conversation

@leonardo-costa-IBM

Copy link
Copy Markdown
Collaborator

Summary
Resolves open Dependabot security alerts reported in issue #725 by adding/updating resolutions in package.json and updating yarn.lock. Also already considered some new audit alerts pointed during this verification.

Changes

Updated vulnerable dependency versions via package resolutions;
Regenerated yarn.lock to enforce secure versions across transitive dependencies.

Resolved Security Alerts

Severity CVE / Advisory Package Fixed Version
🟠 High CVE-2026-102276 / CVE-2026-102278 brace-expansion ^2.1.7
🟠 High CVE-2024-4367 pdfjs-dist ^4.2.67
🟠 High CVE-2026-85730 smol-toml ^1.7.1
🟠 High CVE-2026-85731 basic-ftp ^6.2.1
🟠 High CVE-2020-7692 / GHSA-2c94-w2v8-5h38 extract-zip Removed (upgraded cypress to ^16.1.1)
🟡 Moderate CVE-2026-101912 / CVE-2026-101911 ip-address ^10.7.1
🟡 Moderate CVE-2026-86472 fast-uri ^3.1.8
🟡 Moderate GHSA-6785-g34f-vvhr fast-xml-parser ^5.7.0
🟢 Low GHSA-p98j-92pf-mc4p dompurify ^3.4.16

@rsebade-ibm rsebade-ibm left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me, thanks @leonardo-costa-IBM !

@Palke Palke left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants