Skip to content

chore: Remediate 12 Dependabot security alerts (lockfile only) - #267

Merged
amanabiy merged 1 commit into
mainfrom
dependabot-remediate/security-remediation-20261002
Oct 5, 2026
Merged

amanabiy merged 1 commit into
mainfrom
dependabot-remediate/security-remediation-20261002

Conversation

@amanabiy

@amanabiy amanabiy commented Oct 2, 2026

Copy link
Copy Markdown
Member

This PR updates transitive dependencies in package-lock.json to resolve 12 open security alerts. Changes are lockfile-only, grouped into a single PR to avoid a large number of separate dependency updates.

Alerts addressed

Partially unresolved

brace-expansion 2.x in readdir-glob (dev-only dependency) remains at 2.1.4. Resolving it requires a major bump of readdir-glob's parent chain, which is outside the scope of this lockfile-only change and has no production impact.

How each change was made

All updates are transitive (lockfile splice only — packages are not direct dependencies):

  • axios: patched release available; lockfile entry updated directly via npm audit fix
  • brace-expansion: patched releases available; lockfile entries updated directly

Superseded Dependabot PRs

Each can be restored by commenting on it to reopen — Dependabot will not recreate it automatically for that version.

Merging this PR is expected to resolve 11 of the 12 open alerts. The brace-expansion alert in readdir-glob will remain open.

- axios 1.x: 1.18.1 -> 1.20.0 (GHSA-j8rh-479h-cp32, GHSA-4hqw-qxg8-jxx2, GHSA-m8m8-qj5v-23w3,
  GHSA-44g4-m2mj-wpvx, GHSA-r4gj-5m52-g5wh, GHSA-vh66-26gq-q6x8, GHSA-9fr6-4gfg-395g,
  GHSA-x97p-jq2g-jp4f, GHSA-3pq3-5fj3-cg6v)
- brace-expansion 1.x: 1.1.18 -> 1.1.21 (GHSA-q2hr-2g5m-vwhr)
- brace-expansion 2.x: 2.1.4 -> 2.1.7 via glob chain (GHSA-q2hr-2g5m-vwhr)
- brace-expansion 5.x: 5.0.9 -> 5.0.12 (GHSA-q2hr-2g5m-vwhr)
Note: readdir-glob brace-expansion 2.x remains at 2.1.4 (dev-only, needs major bump)
@amanabiy
amanabiy requested a review from a team as a code owner October 2, 2026 16:22
@amanabiy
amanabiy requested review from avinashbot and removed request for a team October 2, 2026 16:22
@amanabiy amanabiy added the dependencies Pull requests that update a dependency file label Oct 2, 2026
@amanabiy
amanabiy requested a review from NathanZlion October 5, 2026 08:47
@amanabiy
amanabiy added this pull request to the merge queue Oct 5, 2026
Merged via the queue into main with commit 28ef548 Oct 5, 2026
44 of 45 checks passed
@amanabiy
amanabiy deleted the dependabot-remediate/security-remediation-20261002 branch October 5, 2026 11:33

This branch was successfully deployed

1 active deployment
dev-pages — f77667d0 Deployed Oct 2, 2026 by amanabiy via deploy / deploy #1252
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants