build: lock file maintenance (main)#32946
Conversation
There was a problem hiding this comment.
Code Review
This pull request updates numerous dependencies in pnpm-lock.yaml. Several security concerns were identified regarding suspicious package versions and the removal of deprecation warnings for vulnerable packages. Specifically, lodash@4.18.1 and express-rate-limit@8.3.2 appear to be non-standard or potentially malicious versions. Additionally, the removal of the deprecation notice for @xmldom/xmldom@0.8.12 is problematic as that version contains known critical vulnerabilities.
90957bd to
f6fddfb
Compare
See associated pull request for more information.
f6fddfb to
1e57f31
Compare
|
This PR was merged into the repository. The changes were merged into the following branches:
|
|
This issue has been automatically locked due to inactivity. Read more about our automatic conversation locking policy. This action has been performed automatically by a bot. |
This PR contains the following updates:
🔧 This Pull Request updates lock files to use the latest dependency versions.