Skip to content

Conversation

@miguelcalderon
Copy link
Contributor

@miguelcalderon miguelcalderon commented Jan 8, 2026

Summary

This PR addresses security vulnerabilities identified by Dependabot.

Branch: miguel/vuln-deps-2026-01-08

Changes

Ran npm audit fix across multiple example folders:

  • examples/angular
  • examples/elm
  • examples/gatsbyjs
  • examples/laravel
  • examples/react
  • examples/typescript
  • examples/webpack

All updates are patch/minor version bumps - no breaking major version changes.

Key Updates

  • @angular-devkit/*: Minor updates
  • undici: Security patches
  • braces: ReDoS vulnerability fix
  • esbuild: Build tool security patches
  • ws: WebSocket security updates

Remaining Vulnerabilities (10)

Package Severity Summary
qs high arrayLimit bypass allows DoS
@parcel/reporter-dev-server medium Origin Validation Error
symfony/http-foundation high Incorrect parsing of PATH_INFO

Addresses 9 high/critical vulnerabilities identified by Dependabot.
@miguelcalderon miguelcalderon self-assigned this Jan 8, 2026
@miguelcalderon miguelcalderon requested a review from a team January 8, 2026 07:31
@miguelcalderon miguelcalderon requested a review from a team January 8, 2026 14:41
Copy link
Member

@divyanshu013 divyanshu013 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me.

@miguelcalderon miguelcalderon merged commit 4276f98 into main Jan 9, 2026
3 checks passed
@miguelcalderon miguelcalderon deleted the miguel/vuln-deps-2026-01-08 branch January 9, 2026 07:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants