Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
These do not block merging, but we recommend reviewing and resolving them:
undici- undici: Information disclosure and Denial of Service via malformed Cache-Control directivesundici@7.28.07.29.0, 8.9.0or higherbrace-expansion- Brace-expansion: Denial of Service due to exponential-time complexitybrace-expansion@5.0.65.0.7, 1.1.16, 2.1.2or higherfast-uri- fast-uri: Security policy bypass due to improper Unicode hostname canonicalizationfast-uri@3.1.24.0.1, 3.1.3, 2.4.2or higherbrace-expansion- Brace-expansion: Denial of Service via memory exhaustion in expand() functionbrace-expansion@5.0.65.0.8, 3.0.3, 2.1.3, 1.1.17or higherundici- undici: Cross-user information disclosure due to improper Cache-Control directive parsingundici@7.28.07.29.0, 8.9.0or higherShow 36 more issues
fast-uri- Fast-uri: Security policy bypass due to URL parsing inconsistencyfast-uri@3.1.22.4.3, 3.1.4, 4.1.1or higherfast-uri- fast-uri: Host confusion vulnerability via backslash in URI authorityfast-uri@3.1.22.4.4, 3.1.5, 4.1.2or higherextract-zip- github.com/maxogden/extract-zip: extract-zip: Arbitrary file write and information disclosure via symlink validation bypassextract-zip@2.0.1nullor higherjs-yaml- js-yaml: Denial of Service via crafted YAML documentsjs-yaml@4.2.03.15.0, 4.3.0or highertar- node-tar: Denial of Service due to incorrect PAX path handlingtar@7.5.167.5.18or highertar- node-tar: Denial of Service via crafted gzip bombtar@7.5.167.5.19or highertar- Node-tar: Denial of Service via malformed tar archive headertar@7.5.167.5.18or higherimmutable- Immutable.js provides many Persistent Immutable data structures. Prior ...immutable@5.1.64.3.9, 5.1.8or higherimmutable- Immutable.js provides many Persistent Immutable data structures. Prior ...immutable@5.1.64.3.9, 5.1.8or highernanoid- nanoid: Denial of Service via infinite loop in random ID generationnanoid@3.3.153.3.18, 5.1.6or highernanoid- nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ...nanoid@3.3.153.3.16, 5.1.16or higherbrace-expansion- DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationbrace-expansion@5.0.61.1.18, 2.1.4, 3.0.6, 5.0.9or higherpostcss- Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosurepostcss@8.5.158.5.18or highersvgo- SVGO removeScripts plugin leaves some executable scripts intactsvgo@3.3.32.8.3, 3.3.4, 4.0.2or highersvgo- SVGO removeScripts plugin leaves some executable scripts intactsvgo@4.0.12.8.3, 3.3.4, 4.0.2or higherjs-yaml- Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backportedjs-yaml@4.2.04.3.1, 3.15.1or highersharp- CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591sharp@0.34.50.35.0or higherundici- undici: HTTP header injection via unvalidated blob-like body type propertyundici@7.28.06.28.0, 7.29.0, 8.9.0or higherundici- undici: Response desynchronization via retry interceptor with mismatched Content-Lengthundici@7.28.06.28.0, 7.29.0, 8.9.0or higherundici- Undici: Cookie attribute injection allows bypassing security protectionsundici@7.28.06.28.0, 7.29.0, 8.9.0or higheryaml- yaml: Denial of Service via deeply nested YAML document parsingyaml@2.7.12.8.3, 1.10.3or highermermaid- Mermaid: CSS injection allows altering page elements via diagram inputmermaid@11.15.011.16.1, 10.9.8or higher@astrojs/rss- XML Injection via Unescaped RSS Feed Fields@astrojs/rss@4.0.184.0.19or higherastro- XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)astro@7.0.07.0.6or highertar- node-tar: Denial of Service via crafted archive with NUL bytes in metadatatar@7.5.167.5.17or higherpostcss- PostCSS: Information disclosure via crafted sourceMappingURLpostcss@8.5.158.5.23or highermermaid- Mermaid XY Charts: Denial of Service via invalid X-Axis parametersmermaid@11.15.010.9.8, 11.16.1or highermermaid- Mermaid: Prototype pollution vulnerability allows potential arbitrary code executionmermaid@11.15.011.16.1or highermermaid- Mermaid: Denial of Service via Radar Diagrams 'ticks' parametermermaid@11.15.011.16.1or higherastro- Reflected XSS via unescaped View Transition animation propertiesastro@7.0.07.1.0or higherastro- composableastro/honopipeline bypassessecurity.checkOriginwhenmiddleware()is absent or misorderedastro@7.0.07.0.6or higherdompurify- IN_PLACE hook removal leaves a detached subtree executable, causing XSSdompurify@3.4.113.4.13or highertar- Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selectiontar@7.5.167.5.21or higherastro- Cross-site scripting via unescaped transition:* directive values on hydrated islandsastro@7.0.07.0.4or highermermaid- Mermaid: Prototype pollution vulnerability via configuration APIsmermaid@11.15.011.16.1, 10.9.8or higherdompurify-CUSTOM_ELEMENT_HANDLINGbypassesafterSanitizeElementsfor allowed custom elements.dompurify@3.4.113.4.12or higherView in Plerion