Skip to content

fix: update dependencies to resolve critical security vulnerabilities [3.x]#106

Merged
ManukMinasyan merged 1 commit into3.xfrom
fix/security-deps-3x
Apr 10, 2026
Merged

fix: update dependencies to resolve critical security vulnerabilities [3.x]#106
ManukMinasyan merged 1 commit into3.xfrom
fix/security-deps-3x

Conversation

@ManukMinasyan
Copy link
Copy Markdown
Contributor

Summary

  • Update axios to 1.15.0 (critical SSRF bypass + DoS via __proto__)
  • Update brace-expansion to fix process hang vulnerability
  • Update immutable to fix prototype pollution vulnerability

All fixes applied via npm audit fix.

Copilot AI review requested due to automatic review settings April 10, 2026 10:57
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@ManukMinasyan ManukMinasyan requested a review from Copilot April 10, 2026 10:58
@ManukMinasyan ManukMinasyan self-assigned this Apr 10, 2026
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@ManukMinasyan ManukMinasyan merged commit 52470f5 into 3.x Apr 10, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants