Skip to content

fix: patch 14 npm audit vulnerabilities#50

Merged
tembleking merged 2 commits into
mainfrom
fix/audit-vulnerabilities
May 7, 2026
Merged

fix: patch 14 npm audit vulnerabilities#50
tembleking merged 2 commits into
mainfrom
fix/audit-vulnerabilities

Conversation

@tembleking
Copy link
Copy Markdown
Member

Dependency updates resolve 14 of 17 npm audit vulnerabilities (8 high, 5 moderate, 1 low).

Fixed packages: @isaacs/brace-expansion, ajv, brace-expansion, diff, flatted, follow-redirects, lodash, markdown-it, minimatch, path-to-regexp, picomatch, qs, underscore, undici.

Remaining 3 high (serialize-javascript via mocha@vscode/test-cli) have no upstream fix and are dev-only, not shipped in VSIX.

Update dependencies to resolve 14 of 17 known vulnerabilities.
Remaining 3 (serialize-javascript via mocha/@vscode/test-cli) have
no upstream fix available and are dev-only.
@tembleking tembleking requested a review from a team as a code owner May 7, 2026 08:08
@tembleking tembleking enabled auto-merge (squash) May 7, 2026 08:09
@tembleking tembleking self-assigned this May 7, 2026
alecron
alecron previously approved these changes May 7, 2026
@tembleking tembleking disabled auto-merge May 7, 2026 08:13
@tembleking tembleking enabled auto-merge (squash) May 7, 2026 08:14
@tembleking tembleking merged commit 14eb332 into main May 7, 2026
5 checks passed
@tembleking tembleking deleted the fix/audit-vulnerabilities branch May 7, 2026 08:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants