Skip to content

fix(deps): resolve dependabot security alerts for dev dependencies#234

Open
DimaBir wants to merge 4 commits intomainfrom
fix/dependabot-security-alerts
Open

fix(deps): resolve dependabot security alerts for dev dependencies#234
DimaBir wants to merge 4 commits intomainfrom
fix/dependabot-security-alerts

Conversation

@DimaBir
Copy link
Copy Markdown
Collaborator

@DimaBir DimaBir commented Apr 1, 2026

Summary

Not addressed (separate PR needed)

  • undici (alerts SARIF files from other tooling #33–37): transitive via @actions/http-client@2.2.3 which pins undici@^5.x. Override to 6.x would break semver. Requires @actions/core 2→3 major upgrade.

Test plan

  • npm run build passes
  • npm test — 76/76 passing
  • npm audit confirms alerts resolved

@DimaBir DimaBir requested a review from a team as a code owner April 1, 2026 06:27
@DimaBir DimaBir self-assigned this Apr 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant