Skip to content

Commit 6fb2557

Browse files
alistair3149claude
andcommitted
Bump vulnerable dev-only transitive dependencies to patched versions
Clears the open Dependabot alerts (all development scope, in resources/ext.neowiki/package-lock.json) by updating the affected transitive packages to patched releases within their existing parent ranges. Lockfile only — no package.json or overrides changes. - shell-quote 1.8.3 -> 1.9.0 (critical) - lodash 4.17.23 -> 4.18.1 - postcss 8.5.8 -> 8.5.15 - form-data 4.0.5 -> 4.0.6 - js-cookie 3.0.5 -> 3.0.8 - fast-uri 3.1.0 -> 3.1.2 - js-yaml 4.1.1 -> 4.2.0 - brace-expansion 1.1.13/2.0.3 -> 1.1.15/2.1.1 npm audit now reports 0 vulnerabilities. Build, test and lint pass on Node 24. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
1 parent 4c4f000 commit 6fb2557

1 file changed

Lines changed: 68 additions & 61 deletions

File tree

resources/ext.neowiki/package-lock.json

Lines changed: 68 additions & 61 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)