Skip to content

fix: update vulnerable wasm dev dependencies - #921

Merged
bokuweb merged 1 commit into
mainfrom
codex/fix-dependabot-alerts
Sep 5, 2026
Merged

bokuweb merged 1 commit into
mainfrom
codex/fix-dependabot-alerts

Conversation

@bokuweb

@bokuweb bokuweb commented Sep 5, 2026

Copy link
Copy Markdown
Owner

Summary

  • update pnpm overrides for fast-uri, js-yaml, shell-quote, and brace-expansion to resolve the eight open Dependabot alerts
  • update browserslist and qs to versions that also pass the current pnpm advisory audit
  • regenerate the pnpm lockfile

Verification

  • pnpm install --frozen-lockfile
  • pnpm audit --audit-level moderate (no known vulnerabilities)
  • pnpm test:ci (92 tests and 183 snapshots passed)

@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown

This report was generated by comparing 2e814e6 with 90ea838.
If you would like to check difference, please check here.

success

ArtifactName: wasm

✨✨ That's perfect, there is no visual difference! ✨✨

item count
pass 46
change 0
new 0
delete 0

@bokuweb
bokuweb merged commit 7d2fff4 into main Sep 5, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant