Skip to content

fix(deps): clear the remaining Dependabot advisories - #5

Merged
heyramzi merged 1 commit into
mainfrom
security/dependabot-floors-round2
Aug 25, 2026
Merged

heyramzi merged 1 commit into
mainfrom
security/dependabot-floors-round2

Conversation

@heyramzi

Copy link
Copy Markdown
Owner

Clears the Dependabot advisories that became visible once alerts were switched on for this repo.

Floors are range-scoped and derived from the repo's own live alert data, so each one lands on the highest patched version within the same major line and cannot force a major jump. Packages floored: + "@babel/core + "@xmldom/xmldom + app-builder-lib + brace-expansion + builder-util-runtime + dompurify + electron + esbuild + form-data + linkify-it + lodash + markdown-it + mermaid + path-to-regexp + picomatch + qs + seroval + simple-git + tar + tmp + uuid + vite

Verified with pnpm install --frozen-lockfile in every affected project.

🤖 Generated with Claude Code

https://claude.ai/code/session_011UFpTDiDmWXXtj4iDxjwo6

Range-scoped overrides derived from this repo's live Dependabot alerts, then a
lockfile-only resolve. Verified with pnpm install --frozen-lockfile.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011UFpTDiDmWXXtj4iDxjwo6
@heyramzi
heyramzi force-pushed the security/dependabot-floors-round2 branch from 829d10c to 677262b Compare August 25, 2026 23:18
@heyramzi
heyramzi merged commit 05f3704 into main Aug 25, 2026
1 check passed
@heyramzi
heyramzi deleted the security/dependabot-floors-round2 branch August 25, 2026 23:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant