Skip to content

Fix critical and high npm vulnerabilities - #904

Merged
bigdaz merged 2 commits into
mainfrom
vulnerabilities
Mar 23, 2026
Merged

Fix critical and high npm vulnerabilities #904
bigdaz merged 2 commits into
mainfrom
vulnerabilities

Conversation

@bigdaz

@bigdaz bigdaz commented Mar 23, 2026

Copy link
Copy Markdown
Member

Update transitive dependencies to resolve 4 security vulnerabilities:

  • fast-xml-parser 5.2.0 → 5.5.8 (critical: DoS, entity expansion, stack overflow)
  • flatted 3.3.3 → 3.4.2 (high: recursion DoS, prototype pollution)
  • minimatch 3.1.2/5.1.6/9.0.5 → 3.1.5/5.1.9/9.0.9 (high: ReDoS)
  • undici 6.23.0/7.21.0 → 6.24.1/7.24.5 (high: WebSocket overflow, HTTP smuggling)

Co-Authored-By: Claude Opus 4.6 (1M context) noreply@anthropic.com

bigdaz and others added 2 commits March 23, 2026 10:19
Update transitive dependencies to resolve 4 security vulnerabilities:
- fast-xml-parser 5.2.0 → 5.5.8 (critical: DoS, entity expansion, stack overflow)
- flatted 3.3.3 → 3.4.2 (high: recursion DoS, prototype pollution)
- minimatch 3.1.2/5.1.6/9.0.5 → 3.1.5/5.1.9/9.0.9 (high: ReDoS)
- undici 6.23.0/7.21.0 → 6.24.1/7.24.5 (high: WebSocket overflow, HTTP smuggling)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@bigdaz
bigdaz merged commit 8bfa39f into main Mar 23, 2026
124 of 126 checks passed
@bigdaz
bigdaz deleted the vulnerabilities branch March 23, 2026 17:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant