Skip to content

Comments

Fix dependabot updates#367

Draft
cl-efornaciari wants to merge 4 commits intodevelopfrom
fix/dependabot-updates
Draft

Fix dependabot updates#367
cl-efornaciari wants to merge 4 commits intodevelopfrom
fix/dependabot-updates

Conversation

@cl-efornaciari
Copy link
Contributor

No description provided.

…f-5jf3), refresh root pnpm lockfile

Signed-off-by: Eric Fornaciari <eric.fornaciari@smartcontract.com>
Regenerated pnpm-lock.yaml files to pick up patched transitive deps:
- lodash 4.17.23 (CVE-2025-13465)
- undici 6.23.0 (CVE-2026-22036)
- js-yaml 3.14.2 (CVE-2025-64718)
- tmp 0.2.5 in contracts/ (CVE-2025-54798)

Signed-off-by: Eric Fornaciari <eric.fornaciari@smartcontract.com>
Tidy go.mod/go.sum after go-ethereum v1.17.0 bump.
All modules build successfully.

Signed-off-by: Eric Fornaciari <eric.fornaciari@smartcontract.com>
Required by eslint-plugin-prettier (optional peer dep) — was
previously auto-resolved in old lockfile but dropped on refresh.

Signed-off-by: Eric Fornaciari <eric.fornaciari@smartcontract.com>
@github-actions
Copy link
Contributor

✅ API Diff Results - No breaking changes


📄 View full apidiff report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant