chore(deps): fix open Dependabot alerts - #572
Conversation
- quinn-proto 0.11.14 -> 0.11.15 (CLI, CVE-2026-XXXXX memory exhaustion) - body-parser 1.20.5 -> 1.20.6 (coworker/gui via express) - vite 5.4 -> 6.4 (chrome-extension dev stack) - vitest 2 -> 3.2 (chrome-extension, critical UI server advisory) - postcss 8.5.15 -> 8.5.26, esbuild 0.21 -> 0.25, nanoid -> 3.3.18 - vite-plugin-static-copy 1.x -> 3.4 - js-yaml 3.14.2 -> 3.15.1, brace-expansion 1.1.15 -> 1.1.18 (browser test fixtures)
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (4)
📒 Files selected for processing (1)
Included review availability: Your plan includes up to 4 reviews per rolling hour; 3 remain after this review. 📝 WalkthroughWalkthroughThe extension updates its Vite, ChangesExtension tooling
Estimated code review effort: 1 (Trivial) | ~2 minutes Merge Risk: ⚪ Minimal · up to This PR updates vulnerable dependency versions and lockfiles across the affected projects, with the stated tests, builds, and audits passing; no actionable merge-blocking risk remains beyond normal checks. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Bumps the packages behind all 14 open Dependabot alerts on the default branch:
Verified: cargo test (CLI), vitest run + vite build (chrome-extension), coworker GUI node tests, npm audit 0 vulnerabilities in all three npm manifests.
Summary by CodeRabbit