Skip to content

chore: upgrade dependencies - #53

Merged
orbivort merged 1 commit into
mainfrom
chore/upgrade-dependencies
Sep 5, 2026
Merged

orbivort merged 1 commit into
mainfrom
chore/upgrade-dependencies

Conversation

@orbivort

@orbivort orbivort commented Sep 5, 2026

Copy link
Copy Markdown
Owner

Description

Upgrade dependencies

Type of Change

  • Security improvement

Changes Made

Security

  • Remediate high- and moderate-severity transitive dependency vulnerabilities:
    • browserslist → 4.28.8 — fixes unbounded memory growth (no cache eviction) from
      distinct query results leading to eventual OOM
      (GHSA-c83g-rgw3-j3cx) and an
      uncaught crash / prototype write via untrusted browserslist-stats.json custom stats
      (GHSA-73wf-gq98-2v4g). It is pulled
      by @babel/helper-compilation-targets, core-js-compat, doiuse, and
      stylelint-no-unsupported-browser-features
    • mysql2 3.15.3 → 3.24.3 — fixes an auth-plugin downgrade to mysql_clear_password
      that leaks plaintext credentials
      (GHSA-3f6p-5ww8-9rcr) and an
      unbounded zlib-inflate decompression-bomb DoS in the compressed protocol handler
      (GHSA-rgwj-5xj2-c3m3). It is pulled
      by the Prisma CLI, which pins the vulnerable version exactly
    • fast-uri 3.1.5 → 3.1.7 — fixes SSRF / host confusion via malformed IPv6,
      percent-decoding, and IDN normalization
      (GHSA-5jgf-p345-68v8,
      GHSA-f65p-4m7j-42xc,
      GHSA-fph4-wmhf-6fwf,
      GHSA-jqff-g426-hqxp). It is pulled by
      ajv through the commitlint and stylelint toolchains
    • qs 6.15.3 → 6.16.0 — fixes an array-limit bypass via bracket-key comma parsing
      (GHSA-x5fp-wj9c-mxmx) and a DoS via
      an attacker-controlled isBuffer
      (GHSA-4mjr-xmp4-gh2g). It is pulled
      by Express, body-parser, and superagent

@orbivort
orbivort merged commit dfa86be into main Sep 5, 2026
18 checks passed
@orbivort
orbivort deleted the chore/upgrade-dependencies branch September 5, 2026 08:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant