Skip to content

security: fix vulnerable transitive npm dependencies#346

Open
Avi-Bendetsky wants to merge 1 commit intoruvnet:mainfrom
Avi-Bendetsky:fix/security-deps-update
Open

security: fix vulnerable transitive npm dependencies#346
Avi-Bendetsky wants to merge 1 commit intoruvnet:mainfrom
Avi-Bendetsky:fix/security-deps-update

Conversation

@Avi-Bendetsky
Copy link
Copy Markdown

Summary

Context

These were flagged by Dependabot in the downstream consumer BAS-More/RuView which uses ruvector as a git submodule.

Test plan

  • cd npm && npm install resolves without errors
  • npm audit shows no high/critical vulnerabilities from overridden packages

🤖 Generated with claude-flow

Pins node-forge>=1.4.0, flatted>=3.3.3, picomatch>=4.0.3,
lodash>=4.17.22, brace-expansion>=2.0.2 via package.json overrides
to resolve Dependabot alerts downstream in BAS-More/RuView.

Co-Authored-By: claude-flow <ruv@ruv.net>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant