Skip to content

DEV-6794: bump brace-expansion, fast-uri, nanoid to clear npm audit highs - #78

Merged
borisd merged 1 commit into
mainfrom
dev-6794-xyte-cli-clear-npm-audit-high-advisories-brace-expansion
Sep 10, 2026
Merged

borisd merged 1 commit into
mainfrom
dev-6794-xyte-cli-clear-npm-audit-high-advisories-brace-expansion

Conversation

@ariel-greenfeld

Copy link
Copy Markdown
Contributor

Fixes the security CI job (npm audit --audit-level=high) that currently fails on every open PR in this repo.

Lockfile-only bumps of three dev-only transitive deps, all within the ranges package.json already declares:

Package Via Before After Advisory
brace-expansion eslint → minimatch 5.0.8 5.0.9 GHSA-rgw5-rvv9-x895
fast-uri ajv 3.1.4 3.1.7 5 host-confusion / SSRF advisories
nanoid vitest → vite → postcss 3.3.16 3.3.18 GHSA-2v37-7h3g-55p8

npm audit --omit=dev was already clean, so the published @xyteai/cli package is not affected. npm audit --audit-level=high now exits 0; full vitest suite passes (1247 tests).

Two moderate advisories (@humanfs/node, @vitest/mocker) are left as-is: their fixes are major bumps and npm update crashes on them with an npm internal error. The CI gate is high-only.

Linear: https://linear.app/xyte/issue/DEV-6794

🤖 Generated with Claude Code

…ighs

Lockfile-only bumps within existing ranges (dev deps via eslint, ajv, vitest).
Clears the security CI job (npm audit --audit-level=high) that fails on every PR.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 10, 2026 14:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@borisd
borisd merged commit fc03cf0 into main Sep 10, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants