Skip to content

Fix CVEs: postcss, js-yaml, svgo, fast-uri, brace-expansion, react-router-dom - #137

Merged
mraible merged 2 commits into
mainfrom
fix/cve-july-2026
Aug 11, 2026
Merged

Fix CVEs: postcss, js-yaml, svgo, fast-uri, brace-expansion, react-router-dom#137
mraible merged 2 commits into
mainfrom
fix/cve-july-2026

Conversation

@mraible

@mraible mraible commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

Updates dependencies to resolve security vulnerabilities:

  • react-router-dom 7.17.0 → 7.18.2 (multiple CVEs)
  • postcss 8.5.14 → 8.5.18 (direct devDependency update)
  • js-yaml → 4.3.0 (prototype pollution)
  • svgo → 3.3.4
  • fast-uri → 3.1.5 (ReDoS)
  • brace-expansion@1 → 1.1.16, brace-expansion@5 → 5.0.7 (ReDoS)

…brace-expansion 1.1.16/5.0.7, react-router-dom 7.18.2
@mraible
mraible requested a review from a team August 10, 2026 16:01
The Falcon console now renders extension headers as button elements
with aria-expanded attributes instead of h1 headings. Use
getByRole('button') to match, consistent with the foundry-playwright
library's expandExtensionInSocket() method.
@mraible
mraible enabled auto-merge (squash) August 10, 2026 19:14
@mraible
mraible merged commit 0d8577a into main Aug 11, 2026
11 checks passed
@mraible
mraible deleted the fix/cve-july-2026 branch August 11, 2026 15:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants