Skip to content

chore: update changelog for v3.0.5 [3.x]#107

Merged
ManukMinasyan merged 1 commit into3.xfrom
chore/changelog-3x-v305
Apr 10, 2026
Merged

chore: update changelog for v3.0.5 [3.x]#107
ManukMinasyan merged 1 commit into3.xfrom
chore/changelog-3x-v305

Conversation

@ManukMinasyan
Copy link
Copy Markdown
Contributor

Add v3.0.5 changelog entry for security fixes.

Copilot AI review requested due to automatic review settings April 10, 2026 11:01
@ManukMinasyan ManukMinasyan merged commit 35b5e91 into 3.x Apr 10, 2026
4 checks passed
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a v3.0.5 release entry to the changelog to document security-related dependency updates for the 3.x line.

Changes:

  • Add a new v3.0.5 section dated 2026-04-10
  • Document security dependency updates (axios, brace-expansion, immutable)

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +13 to +14
- Update brace-expansion to fix process hang vulnerability
- Update immutable to fix prototype pollution vulnerability
Copy link

Copilot AI Apr 10, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Security section mixes dependency updates with and without explicit target versions (axios includes 1.15.0, but brace-expansion/immutable do not). For auditability and consistency, include the updated versions (and ideally CVE/GHSA or PR refs if available) for brace-expansion and immutable as well.

Suggested change
- Update brace-expansion to fix process hang vulnerability
- Update immutable to fix prototype pollution vulnerability
- Update brace-expansion to 2.0.2 to fix the process hang vulnerability (GHSA-v6h2-p8h4-qcjw)
- Update immutable to 4.3.7 to fix the prototype pollution vulnerability (GHSA-h3fm-h5jp-5f6v)

Copilot uses AI. Check for mistakes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants