Skip to content

Bump to 0.0.48 and fix npm audit vulnerabilities#205

Merged
dylan-conway merged 1 commit intomainfrom
dylan/npm-audit-0.0.48
Apr 3, 2026
Merged

Bump to 0.0.48 and fix npm audit vulnerabilities#205
dylan-conway merged 1 commit intomainfrom
dylan/npm-audit-0.0.48

Conversation

@dylan-conway
Copy link
Copy Markdown
Collaborator

Summary

  • Bump lodash-es minimum to ^4.18.1 (code injection / prototype pollution fixes)
  • npm audit fix for transitive deps: ajv, brace-expansion, flatted, minimatch, picomatch, yaml
  • Bump package version 0.0.47 → 0.0.48

Resolves 7 advisories (4 high, 3 moderate). npm audit now reports 0 vulnerabilities.

Test plan

  • npm audit → 0 vulnerabilities
  • npm run typecheck passes
  • npm run lint:check passes

- Bump lodash-es to ^4.18.1 (fixes GHSA-r5fr-rjxr-66jc, GHSA-f23m-r3pf-42rh)
- Update transitive deps via npm audit fix: ajv, brace-expansion, flatted,
  minimatch, picomatch, yaml
- Bump package version to 0.0.48
@dylan-conway dylan-conway merged commit bc3f0fa into main Apr 3, 2026
11 of 12 checks passed
@dylan-conway dylan-conway mentioned this pull request Apr 3, 2026
4 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants