Skip to content

Bump theme version to 2.15.9 — dependency security fixes - #147

Merged
jasperf merged 1 commit into
mainfrom
chore/dependency-security-fixes-2.15.9
Aug 10, 2026
Merged

Bump theme version to 2.15.9 — dependency security fixes#147
jasperf merged 1 commit into
mainfrom
chore/dependency-security-fixes-2.15.9

Conversation

@jasperf

@jasperf jasperf commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Bumps style.css version 2.15.8 → 2.15.9
  • Adds CHANGELOG entry documenting dependency security fixes

Fixes

  • guzzlehttp/guzzle 7.15.1 → 7.15.3 (Dependabot high: noncanonical host bypass; medium: noncanonical cookie domain scope)
  • nanoid 3.3.16 → 3.3.18 (Dependabot high: custom generators loop indefinitely when size is zero)
  • fast-uri 3.1.4 → 3.1.5 (Dependabot high: host confusion via backslash authority introducer)

All three are transitive dependencies; existing semver ranges already permitted the patched versions.

Synced from imagewize.com monorepo via rsync-theme.sh.

Dependency security fixes: guzzlehttp/guzzle 7.15.1 -> 7.15.3, nanoid 3.3.16 -> 3.3.18, fast-uri 3.1.4 -> 3.1.5.
@jasperf
jasperf merged commit 9f7f147 into main Aug 10, 2026
3 checks passed
@jasperf
jasperf deleted the chore/dependency-security-fixes-2.15.9 branch August 10, 2026 08:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant