Skip to content

chore(deps): npm audit fix (non-breaking) — 126→103 vulns - #26

Merged
solsentry merged 2 commits into
mainfrom
chore/npm-audit-fix
Sep 8, 2026
Merged

solsentry merged 2 commits into
mainfrom
chore/npm-audit-fix

Conversation

@solsentry

Copy link
Copy Markdown
Owner

Lockfile-only npm audit fix (run with npm 11; npm 10.8 crashes in arborist rollback). 126→103 vulnerabilities, 2→1 critical, 30→17 high. next 15.5.15→15.5.25, wrangler 4.86→4.129.1, sharp, undici, axios bumped within semver. Remaining critical/high are all in the @solana/wallet-adapter-wallets chain (trezor / react-native devtools) and require a breaking bump — separate decision.

Verified locally: next build 43/43, opennextjs-cloudflare build OK on node 20.

https://claude.ai/code/session_01YKY8SsyaKD5pUFj6vHPZPq

…al, 30→17 high

Lockfile-only. next 15.5.15→15.5.25, wrangler 4.86→4.129.1, sharp 0.34.5→0.35.4,
undici 7.24.8→7.29.0, axios 1.15.2→1.20.0. Remaining critical/high sit in the
@solana/wallet-adapter-wallets chain (trezor/react-native) and need a breaking
bump (`--force` → wallet-adapter-wallets@0.18.2). Verified: next build 43/43 +
opennextjs-cloudflare build OK on node 20.

Claude-Session: https://claude.ai/code/session_01YKY8SsyaKD5pUFj6vHPZPq
@solsentry
solsentry merged commit 623dbe1 into main Sep 8, 2026
2 checks passed
@solsentry
solsentry deleted the chore/npm-audit-fix branch September 8, 2026 15:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant