Skip to content

version updates for npm deps flagged up as vulnerable by scanner#141

Open
vredchenko wants to merge 1 commit intomainfrom
update-npm-deps
Open

version updates for npm deps flagged up as vulnerable by scanner#141
vredchenko wants to merge 1 commit intomainfrom
update-npm-deps

Conversation

@vredchenko
Copy link
Collaborator

No description provided.

@vredchenko vredchenko changed the title version updates for npm deps fallged up as vulnerable by scanner version updates for npm deps flagged up as vulnerable by scanner Feb 11, 2026
@vredchenko vredchenko marked this pull request as ready for review February 11, 2026 13:25
@akademy akademy self-requested a review March 2, 2026 14:38
Copy link
Member

@akademy akademy left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks good. However, my IDE has flagged up a couple more vulnerabilities (via Mend.io)

It recommends rollup goes to 4.59.0 and storybook to 8.6.17. Can you bump those too?

https://osv.dev/vulnerability/GHSA-mjf5-7g4m-gx5w
https://osv.dev/vulnerability/GHSA-mw96-cpmx-2vgc

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants