Repository navigation
chore: Remediate 12 Dependabot security alerts (lockfile only) - #267
Merged
Merged
Conversation
- axios 1.x: 1.18.1 -> 1.20.0 (GHSA-j8rh-479h-cp32, GHSA-4hqw-qxg8-jxx2, GHSA-m8m8-qj5v-23w3, GHSA-44g4-m2mj-wpvx, GHSA-r4gj-5m52-g5wh, GHSA-vh66-26gq-q6x8, GHSA-9fr6-4gfg-395g, GHSA-x97p-jq2g-jp4f, GHSA-3pq3-5fj3-cg6v) - brace-expansion 1.x: 1.1.18 -> 1.1.21 (GHSA-q2hr-2g5m-vwhr) - brace-expansion 2.x: 2.1.4 -> 2.1.7 via glob chain (GHSA-q2hr-2g5m-vwhr) - brace-expansion 5.x: 5.0.9 -> 5.0.12 (GHSA-q2hr-2g5m-vwhr) Note: readdir-glob brace-expansion 2.x remains at 2.1.4 (dev-only, needs major bump)
NathanZlion
approved these changes
Oct 5, 2026
amanabiy
deleted the
dependabot-remediate/security-remediation-20261002
branch
October 5, 2026 11:33
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR updates transitive dependencies in
package-lock.jsonto resolve 12 open security alerts. Changes are lockfile-only, grouped into a single PR to avoid a large number of separate dependency updates.Alerts addressed
Partially unresolved
brace-expansion 2.x in
readdir-glob(dev-only dependency) remains at 2.1.4. Resolving it requires a major bump ofreaddir-glob's parent chain, which is outside the scope of this lockfile-only change and has no production impact.How each change was made
All updates are transitive (lockfile splice only — packages are not direct dependencies):
npm audit fixSuperseded Dependabot PRs
Each can be restored by commenting on it to reopen — Dependabot will not recreate it automatically for that version.
Merging this PR is expected to resolve 11 of the 12 open alerts. The brace-expansion alert in
readdir-globwill remain open.