Skip to content

Batch security dependency updates (node + ruby)#576

Merged
phoenixy1 merged 2 commits intomasterfrom
ah-batch-dep-security-updates
Apr 23, 2026
Merged

Batch security dependency updates (node + ruby)#576
phoenixy1 merged 2 commits intomasterfrom
ah-batch-dep-security-updates

Conversation

@phoenixy1
Copy link
Copy Markdown
Collaborator

@phoenixy1 phoenixy1 commented Apr 23, 2026

Closes the remaining valid Dependabot PRs (#541, #554, #558, #560, #562, #569, #572, #573) in a single batch.

Changes

node/package-lock.json (via npm audit fix):

ruby/Gemfile.lock (via bundle update addressable):

  • addressable 2.8.10 → 2.9.0

All changes are lock-file only — no direct dependencies were changed.

🤖 Generated with Claude Code

Claude Session: 12b61c0d-b92a-44eb-a624-79e738d5a247

phoenixy1 and others added 2 commits April 22, 2026 17:30
Addresses all open Dependabot security PRs (#541, #554, #558, #562, #569, #572, #573, #560):

node/package-lock.json (via npm audit fix):
- axios 1.13.2 → 1.15.2 (SSRF + header injection CVEs)
- brace-expansion 2.0.2 → 2.1.0 (ReDoS)
- follow-redirects 1.15.11 → 1.16.0 (auth header leak)
- minimatch 5.1.6 → 5.1.9 (multiple ReDoS)
- path-to-regexp 0.1.12 → 0.1.13 (ReDoS)
- picomatch 2.3.1 → 2.3.2 (method injection + ReDoS)
- qs 6.14.1 → 6.14.2 (arrayLimit DoS bypass)

ruby/Gemfile.lock:
- addressable 2.8.10 → 2.9.0

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant