Skip to content

Commit e5b3ea5

Browse files
authored
fix(deps): upgrade lodash, svelte, kit, storybook, tar-fs for security (#3269)
- lodash: ^4.17.21 -> ^4.18.1 (CVE-2026-4800, CVE-2026-2950, CVE-2025-13465) - svelte: 5.53.3 -> 5.55.1 (CVE-2026-27902, CVE-2026-27901) - @sveltejs/kit: 2.53.0 -> 2.55.0 (DoS via form deserialization) - storybook: ^8.6.11 -> ^8.6.18 (CVE-2026-27148) - tar-fs: >=2.1.2 -> ^3.1.2 (CVE-2025-59343) Resolves Dependabot alerts #233, #232, #159, #204, #203, #194, #193, #207, #192, #127.
1 parent c5d4c99 commit e5b3ea5

2 files changed

Lines changed: 606 additions & 679 deletions

File tree

package.json

Lines changed: 32 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -127,23 +127,23 @@
127127
"@eslint/js": "^9.39.2",
128128
"@grpc/grpc-js": "^1.8.22",
129129
"@playwright/test": "^1.55.1",
130-
"@storybook/addon-a11y": "^8.6.11",
131-
"@storybook/addon-actions": "^8.6.4",
132-
"@storybook/addon-docs": "^8.6.11",
133-
"@storybook/addon-essentials": "^8.6.11",
134-
"@storybook/addon-interactions": "^8.6.11",
135-
"@storybook/addon-links": "^8.6.11",
130+
"@storybook/addon-a11y": "^8.6.18",
131+
"@storybook/addon-actions": "^8.6.18",
132+
"@storybook/addon-docs": "^8.6.18",
133+
"@storybook/addon-essentials": "^8.6.18",
134+
"@storybook/addon-interactions": "^8.6.18",
135+
"@storybook/addon-links": "^8.6.18",
136136
"@storybook/addon-svelte-csf": "^5.0.10",
137-
"@storybook/addon-themes": "^8.6.11",
138-
"@storybook/blocks": "^8.6.11",
137+
"@storybook/addon-themes": "^8.6.18",
138+
"@storybook/blocks": "^8.6.18",
139139
"@storybook/icons": "^1.4.0",
140-
"@storybook/svelte": "^8.6.11",
141-
"@storybook/sveltekit": "^8.6.11",
142-
"@storybook/test": "^8.6.11",
140+
"@storybook/svelte": "^8.6.18",
141+
"@storybook/sveltekit": "^8.6.18",
142+
"@storybook/test": "^8.6.18",
143143
"@storybook/test-runner": "^0.22.0",
144144
"@sveltejs/adapter-static": "^3.0.8",
145145
"@sveltejs/adapter-vercel": "^6.3.2",
146-
"@sveltejs/kit": "2.53.0",
146+
"@sveltejs/kit": "2.55.0",
147147
"@sveltejs/vite-plugin-svelte": "^6.2.4",
148148
"@temporalio/activity": "1.15.0",
149149
"@temporalio/client": "1.15.0",
@@ -190,7 +190,7 @@
190190
"husky": "^8.0.3",
191191
"jsdom": "^20.0.3",
192192
"lint-staged": "^16.2.7",
193-
"lodash": "^4.17.21",
193+
"lodash": "^4.18.1",
194194
"mkdirp": "^2.1.3",
195195
"mock-socket": "^9.1.5",
196196
"nanoid": "^5.1.5",
@@ -215,19 +215,19 @@
215215
"remark-parse": "^10.0.2",
216216
"remark-toc": "^8.0.1",
217217
"rimraf": "^4.3.1",
218-
"storybook": "^8.6.11",
218+
"storybook": "^8.6.18",
219219
"stylelint": "^17.0.0",
220220
"stylelint-config-recommended": "^18.0.0",
221221
"stylelint-config-standard": "^40.0.0",
222-
"svelte": "5.53.3",
222+
"svelte": "5.55.1",
223223
"svelte-check": "^4.1.5",
224224
"svelte-eslint-parser": "^1.4.1",
225225
"svelte-highlight": "^7.8.2",
226226
"svelte-loader": "^3.2.4",
227227
"svelte-preprocess": "^6.0.3",
228228
"svelte2tsx": "^0.7.35",
229229
"tailwindcss": "^3.4.1",
230-
"tar-fs": ">=2.1.2",
230+
"tar-fs": "^3.1.2",
231231
"tslib": "^2.4.1",
232232
"typescript": "^5.2.2",
233233
"typescript-eslint": "^8.54.0",
@@ -248,11 +248,25 @@
248248
},
249249
"pnpm": {
250250
"overrides": {
251-
"devalue": "5.6.2",
251+
"devalue": "5.6.4",
252252
"axios": "1.12.0",
253253
"cookie": "0.7.0",
254254
"micromatch": "^4.0.8",
255-
"esbuild": "^0.25.0"
255+
"esbuild": "^0.25.0",
256+
"serialize-javascript": "^7.0.5",
257+
"picomatch@>=4": "^4.0.4",
258+
"rollup": "^4.60.1",
259+
"flatted": "^3.4.2",
260+
"tar": "^7.5.13",
261+
"minimatch@>=3 <4": "^3.1.5",
262+
"minimatch@>=5 <6": "^5.1.9",
263+
"minimatch@>=8 <9": "^8.0.7",
264+
"minimatch@>=9 <10": "^9.0.9",
265+
"minimatch@>=10": "^10.2.5",
266+
"koa": "^3.2.0",
267+
"yaml": "^2.8.3",
268+
"qs": "^6.15.0",
269+
"effect": "^3.21.0"
256270
},
257271
"onlyBuiltDependencies": [
258272
"@swc/core",

0 commit comments

Comments
 (0)