Skip to content

Clear the open dependabot alerts in the lockfile - #17

Merged
mattrbeck merged 1 commit into
masterfrom
fix/dependabot-alerts
Sep 3, 2026
Merged

mattrbeck merged 1 commit into
masterfrom
fix/dependabot-alerts

Conversation

@mattrbeck

Copy link
Copy Markdown
Owner

Closes the six open npm advisories. All of them are transitive dev dependencies, and every patched version already sits inside a range package.json allows, so nothing but package-lock.json moves.

package was now why
fast-uri 3.1.5 3.1.7 alerts #34, #35, #37, #38 (high)
@humanfs/node 0.16.7 0.16.8 alert #36 (moderate)
postcss-selector-parser 7.1.0 7.1.6 alert #33 (low)
browserslist 4.26.2 4.28.8 GHSA-c83g-rgw3-j3cx, GHSA-73wf-gq98-2v4g

The browserslist one is not a Dependabot alert — npm audit surfaced it after the first three bumps, so it rides along here rather than waiting for its own alert. Its dependency tail (caniuse-lite, electron-to-chromium, node-releases, baseline-browser-mapping, update-browserslist-db) moves with it, plus @humanfs/core/@humanfs/types behind @humanfs/node.

Verified: npm audit reports 0 vulnerabilities, npm test passes 176/176 across 8 suites, and npm run lint (eslint + stylelint) is clean.

fast-uri 3.1.5 -> 3.1.7, @humanfs/node 0.16.7 -> 0.16.8 and
postcss-selector-parser 7.1.0 -> 7.1.6 cover the five npm advisories
Dependabot had open. `npm audit` then turned up a sixth that Dependabot
had not filed, browserslist 4.26.2 -> 4.28.8, so that one goes too.

Every bump sits inside a range package.json already allows, so only the
lockfile moves. Tests and both linters pass, and `npm audit` is clean.
@mattrbeck
mattrbeck merged commit 7043b39 into master Sep 3, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant