Commit 6fb2557
Bump vulnerable dev-only transitive dependencies to patched versions
Clears the open Dependabot alerts (all development scope, in
resources/ext.neowiki/package-lock.json) by updating the affected
transitive packages to patched releases within their existing parent
ranges. Lockfile only — no package.json or overrides changes.
- shell-quote 1.8.3 -> 1.9.0 (critical)
- lodash 4.17.23 -> 4.18.1
- postcss 8.5.8 -> 8.5.15
- form-data 4.0.5 -> 4.0.6
- js-cookie 3.0.5 -> 3.0.8
- fast-uri 3.1.0 -> 3.1.2
- js-yaml 4.1.1 -> 4.2.0
- brace-expansion 1.1.13/2.0.3 -> 1.1.15/2.1.1
npm audit now reports 0 vulnerabilities. Build, test and lint pass on Node 24.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>1 parent 4c4f000 commit 6fb2557
1 file changed
Lines changed: 68 additions & 61 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments