Skip to content

fix security dependabot alerts - #83

Merged
hit9 merged 3 commits into
masterfrom
fix-security-dependabot-alerts
Jun 19, 2026
Merged

hit9 merged 3 commits into
masterfrom
fix-security-dependabot-alerts

Conversation

@hit9

@hit9 hit9 commented Jun 19, 2026

Copy link
Copy Markdown
Owner
  • make: add publish alias for upload-pip-package
  • fix(deps): resolve Dependabot npm alerts in the vscode extension

hit9 and others added 3 commits June 19, 2026 05:24
All Dependabot alerts came from the vscode extension's npm dependencies
(transitive dev tooling: eslint/mocha/glob → ajv, brace-expansion, diff,
flatted, js-yaml, minimatch, picomatch, serialize-javascript, ...).

- `npm audit fix` updated the lockfile, clearing 7 of 9 (all runtime
  vulnerabilities included).
- The remaining 2 were serialize-javascript (<=7.0.4, RCE/DoS) pulled in
  by mocha, which still pins the 6.x line. npm's --force fix would
  *downgrade* mocha; instead pin the patched version via an override:
  "overrides": { "serialize-javascript": "^7.0.6" }.

`npm audit` now reports 0 vulnerabilities; `tsc -p ./` still compiles and
`npm ci` validates the lockfile. The Python (>= ranges) and Go (local
modules) manifests have no vulnerable pins.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@hit9
hit9 merged commit bd9aea1 into master Jun 19, 2026
6 checks passed
@hit9
hit9 deleted the fix-security-dependabot-alerts branch June 19, 2026 12:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant