Skip to content

fix/dependabot-security-updates#203

Merged
SchnozzleCat merged 1 commit intomainfrom
fix/dependabot-security-updates
Apr 14, 2026
Merged

fix/dependabot-security-updates#203
SchnozzleCat merged 1 commit intomainfrom
fix/dependabot-security-updates

Conversation

@SchnozzleCat
Copy link
Copy Markdown
Contributor

Summary

  • Update axios from ^1.7.2 to ^1.15.0 (fixes SSRF and header injection vulnerabilities - alerts 86, 88, 89)
  • Update semantic-release from ^25.0.1 to ^25.0.3 (fixes undici vulnerabilities)

Non-breaking fixes applied

These updates were applied via npm audit fix and do not require breaking changes.

Remaining Dependabot alerts (require breaking changes)

The following alerts cannot be fixed without breaking changes:

  • elliptic → requires storybook@7 (major refactor)
  • prismjs → requires boemly@1.6.0 (breaking API changes)
  • @tootallnate/once → requires jest@30 (breaking)
  • picomatch/brace-expansion → bundled in npm, cannot fix
  • undici → still present in semantic-release (locked to older @actions/http-client)
  • next vulnerabilities → next is a peer dependency, cannot be updated here

@vercel
Copy link
Copy Markdown

vercel bot commented Apr 13, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
storybook Ready Ready Preview, Comment Apr 14, 2026 10:32am

Request Review

@github-actions
Copy link
Copy Markdown

github-actions bot commented Apr 13, 2026

size-limit report 📦

Path Size
dist/index.js 605.47 KB (+0.29% 🔺)

- Update axios from ^1.7.2 to ^1.15.0 (fixes SSRF and header injection vulnerabilities - alerts 86, 88, 89)
- Update semantic-release from ^25.0.1 to ^25.0.3 (fixes undici vulnerabilities)

Note: Additional vulnerabilities require breaking changes:
- elliptic → requires storybook@7 (major refactor)
- prismjs → requires boemly@1.6.0 (breaking API changes)
- @tootallnate/once → requires jest@30 (breaking)
- picomatch/brace-expansion → bundled in npm, cannot fix
- undici → bundled in semantic-release
@SchnozzleCat SchnozzleCat merged commit 53b8dec into main Apr 14, 2026
8 checks passed
@SchnozzleCat SchnozzleCat deleted the fix/dependabot-security-updates branch April 14, 2026 12:34
@github-actions
Copy link
Copy Markdown

🎉 This PR is included in version 8.4.1 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants