fix(deps): clear brace-expansion and axios advisories - #648
Merged
Merged
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Contributor
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Complexity | 0 |
NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.
The web override pinned axios to >=1.18.0, which resolved to 1.18.1, inside the vulnerable 1.0.0-1.19.0 range flagged by npm audit --audit-level=high. That failure is pre-existing on main (Security Scan red since 2026-09-13) and was the only remaining high-severity finding. axios is reachable only via wait-on, a devDependency that requires ^1.18.1, so ^1.19.1 (resolving to 1.20.0) stays compatible. Verified: npm ci exit 0; npm audit --audit-level=high -> 0 vulnerabilities; npm test -> 18 files, 175 tests passing. Refs #648
cline-cloud Bot
pushed a commit
that referenced
this pull request
Oct 1, 2026
* docs: update human-facing docs and AGENTS.md workflow * fix(deps): update brace-expansion to resolve dependency audit vulnerability * chore(deps): move brace-expansion bump to its own PR (#648) * docs: complete AGENTS.md index tables and add README ToC AGENTS.md listed 4 of the 16 documents in agents-docs/ and 5 of the 16 skills in .agents/skills/. Both tables are now complete, with descriptions taken from each skill's own frontmatter. README.md is 178 lines with 19 headings and had no Table of Contents, which readme-best-practices flags as a defect for READMEs over 100 lines. Anchors for the repeated "Rust CLI (do-wdr)" and "Web UI" headings use the -1 suffix GitHub generates. markdownlint-cli2: 0 issues. Refs #647 * fix(deps): update axios and package-lock to resolve npm audit vulnerability --------- Co-authored-by: d-oit <dominik.oswald@example.com>
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Two
web/package.jsonoverrides were resolving into vulnerable ranges, andbetween them were the only reason
Dependency Auditwas red:brace-expansion5.0.95.0.12axios>=1.18.0(resolved 1.18.1)^1.19.1(resolved 1.20.0)Cleared by the
brace-expansionbump:< 5.0.10< 5.0.11< 5.0.12Cleared by the
axiosbump: 12 advisories against1.0.0 - 1.19.0, includingprototype pollution, header injection, and redirect-based SSRF.
axiosis reachable only throughwait-on, adevDependencythat requires^1.18.1, so1.20.0stays compatible.Verification
npm ci-> exit 0npm audit --audit-level=high-> 0 vulnerabilitiesnpm test-> 18 test files, 175 tests passedScope
The
brace-expansionbump was split out of #647, where it sat under adocs:title. The
axiosbump is a pre-existing failure onmain(Security Scan hasbeen red since 2026-09-13) and was the last high-severity finding, so it is
folded in here rather than left as a separate follow-up.