Skip to content

[codex] update vulnerable npm dependencies - #147

Merged
greenthree merged 1 commit into
mainfrom
codex/dependabot-security-updates
Aug 9, 2026
Merged

[codex] update vulnerable npm dependencies#147
greenthree merged 1 commit into
mainfrom
codex/dependabot-security-updates

Conversation

@greenthree

Copy link
Copy Markdown
Owner

Summary

Dependency changes

  • postcss: 8.5.17 -> 8.5.26
  • react-router / react-router-dom: 7.18.1 -> 7.18.2
  • nanoid: 3.3.16 -> 3.3.18
  • js-yaml: 4.3.0 -> 4.3.1
  • brace-expansion: 1.1.16 -> 1.1.18 and 5.0.7 -> 5.0.9

This is a lockfile-only change. It supersedes the stale PostCSS-only Dependabot PR #111; the existing handoff audit PR #146 is intentionally unaffected.

Validation

  • npm ci
  • npm audit --audit-level=high
  • npm audit --omit=dev --audit-level=high
  • npm run lint
  • npm test
  • npm run build
  • git diff --check

@greenthree
greenthree marked this pull request as ready for review August 9, 2026 07:40
@greenthree
greenthree merged commit c69d77c into main Aug 9, 2026
4 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant