Skip to content

chore: upgrade dependencies for security fixes#139

Merged
HsiangNianian merged 3 commits intomainfrom
upgrade-dependencies
Apr 1, 2026
Merged

chore: upgrade dependencies for security fixes#139
HsiangNianian merged 3 commits intomainfrom
upgrade-dependencies

Conversation

@hydroroll-bot
Copy link
Copy Markdown
Member

升级依赖以修复安全漏洞:

  • axios: 1.13.2 -> 1.13.5 (fixes CVE-2026-25639)
  • dompurify: 3.3.1 -> 3.3.2
  • express-rate-limit: 8.2.1 -> 8.2.2
  • hono: 4.12.2 -> 4.12.4
  • @hono/node-server: 1.19.10
  • @isaacs/brace-expansion: 5.0.1
  • lodash: 4.17.21 -> 4.17.23
  • minimatch: 10.1.1 -> 10.2.3
  • path-to-regexp: 0.1.12 -> 0.1.13
  • picomatch: 2.3.1 -> 2.3.2
  • qs: 6.14.1 -> 6.14.2
  • seroval: 1.3.2 -> 1.4.1

- axios: 1.13.2 -> 1.13.5 (fixes CVE-2026-25639)
- dompurify: 3.3.1 -> 3.3.2
- express-rate-limit: 8.2.1 -> 8.2.2
- hono: 4.12.2 -> 4.12.4
- @hono/node-server: 1.19.10
- @isaacs/brace-expansion: 5.0.1
- lodash: 4.17.21 -> 4.17.23
- minimatch: 10.1.1 -> 10.2.3
- path-to-regexp: 0.1.12 -> 0.1.13
- picomatch: 2.3.1 -> 2.3.2
- qs: 6.14.1 -> 6.14.2
- seroval: 1.3.2 -> 1.4.1
@vercel
Copy link
Copy Markdown

vercel bot commented Apr 1, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
drop-out-docs Ready Ready Preview, Comment Apr 1, 2026 3:56am

@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Apr 1, 2026

Workspace change through: d4912de

1 changesets found

Planned changes to release
Package Bump Level Current Version Next Version
@dropout/docs patch 0.1.0-alpha.1 0.1.0-alpha.2

@HsiangNianian HsiangNianian added priority: high HighPriority Stuff dependencies Pull requests that update a dependency file package: ui labels Apr 1, 2026
@HsiangNianian HsiangNianian merged commit 1016a53 into main Apr 1, 2026
14 of 16 checks passed
@HsiangNianian HsiangNianian deleted the upgrade-dependencies branch April 1, 2026 04:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file package: ui priority: high HighPriority Stuff

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants