Skip to content

Upgrade dependencies to fix security vulnerabilities#393

Merged
mraible merged 2 commits into
mainfrom
upgrade-security-deps
May 19, 2026
Merged

Upgrade dependencies to fix security vulnerabilities#393
mraible merged 2 commits into
mainfrom
upgrade-security-deps

Conversation

@mraible
Copy link
Copy Markdown
Contributor

@mraible mraible commented May 18, 2026

Upgrades dependencies across the monorepo to address 30 open Dependabot alerts.

Direct upgrades (shared/mitre-vue, remediations, chart-vue):

Resolutions added/updated (root package.json):

All tests pass (35 tests across 3 workspaces). Rebuilt tracked dist artifacts.

- vite 7.3.1 → 7.3.2 (CVE-2026-39363, CVE-2026-39364, CVE-2026-39365)
- axios resolution 1.13.6 → 1.15.2 (CVE-2025-62718, CVE-2026-40175, CVE-2026-42033 through CVE-2026-42044, CVE-2026-42264)
- Add postcss 8.5.14 resolution (CVE-2026-41305)
- Add uuid 13.0.1 resolution (CVE-2026-41907)
- Add ip-address 10.1.1 resolution (CVE-2026-42338)
- Add follow-redirects 1.16.0 resolution (header leak to cross-domain redirects)
@mraible mraible requested a review from a team May 18, 2026 14:42
Fixes TypeScript patch hash mismatch that caused CI immutable install to fail.
@mraible mraible enabled auto-merge (squash) May 18, 2026 15:17
@mraible mraible merged commit 5ed02bd into main May 19, 2026
5 checks passed
@mraible mraible deleted the upgrade-security-deps branch May 19, 2026 12:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants