Skip to content

chore(deps): update npm to fix security vulnerabilities#50

Merged
joakimen merged 1 commit intomasterfrom
fix/npm-vulnerabilities
Feb 5, 2026
Merged

chore(deps): update npm to fix security vulnerabilities#50
joakimen merged 1 commit intomasterfrom
fix/npm-vulnerabilities

Conversation

@joakimen
Copy link
Contributor

@joakimen joakimen commented Feb 5, 2026

Summary

  • Updates npm from 11.8.0 to 11.9.0 (transitive dependency via @semantic-release/npm)
  • Fixes 3 high severity vulnerabilities in bundled dependencies:
    • @isaacs/brace-expansion - Uncontrolled Resource Consumption
    • tar - Arbitrary File Creation/Overwrite via Hardlink Path Traversal
    • npm - Local Privilege Escalation

Updates npm from 11.8.0 to 11.9.0 to resolve high severity vulnerabilities
in bundled dependencies (@isaacs/brace-expansion, tar).
@joakimen joakimen merged commit 3ce779f into master Feb 5, 2026
3 checks passed
@joakimen joakimen deleted the fix/npm-vulnerabilities branch February 5, 2026 11:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant