Skip to content

fix(deps): update vulnerable build dependencies - #28

Merged
Baskerville42 merged 2 commits into
mainfrom
dependabot/npm_and_yarn/svgo-4.1.0
Sep 9, 2026
Merged

fix(deps): update vulnerable build dependencies#28
Baskerville42 merged 2 commits into
mainfrom
dependabot/npm_and_yarn/svgo-4.1.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 9, 2026

Copy link
Copy Markdown
Contributor

Summary

  • update svgo from 4.0.2 to 4.1.0
  • update js-yaml from 4.3.1 to 4.3.2
  • keep the fast-uri 3.1.7 security fix already merged into main

The updates are intentionally combined because either isolated Dependabot PR leaves another high-severity advisory in the lockfile and therefore cannot pass the required npm audit check.

Supersedes #29.

Verification

  • npm ci --ignore-scripts --no-audit --no-fund
  • npm run verify
  • npm audit --audit-level=high — 0 vulnerabilities
  • npm audit signatures — 592 verified registry signatures and 157 verified attestations

@dependabot dependabot Bot added dependencies Dependency updates javascript JavaScript and TypeScript ecosystem labels Sep 9, 2026
@dependabot
dependabot Bot requested a review from Baskerville42 as a code owner September 9, 2026 09:52
@dependabot dependabot Bot added javascript JavaScript and TypeScript ecosystem dependencies Dependency updates labels Sep 9, 2026
@codecov

codecov Bot commented Sep 9, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

nastyabon8
nastyabon8 previously approved these changes Sep 9, 2026
Baskerville42
Baskerville42 previously approved these changes Sep 9, 2026
Bumps [svgo](https://github.com/svg/svgo) from 4.0.2 to 4.1.0.
- [Release notes](https://github.com/svg/svgo/releases)
- [Commits](svg/svgo@v4.0.2...v4.1.0)

---
updated-dependencies:
- dependency-name: svgo
  dependency-version: 4.1.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/svgo-4.1.0 branch from 1536992 to 76e68e0 Compare September 9, 2026 19:56
@Baskerville42
Baskerville42 dismissed stale reviews from nastyabon8 and themself via a1a645f September 9, 2026 20:08
@Baskerville42 Baskerville42 changed the title build(deps): bump svgo from 4.0.2 to 4.1.0 fix(deps): update vulnerable build dependencies Sep 9, 2026
@Baskerville42
Baskerville42 self-requested a review September 9, 2026 20:10
@Baskerville42
Baskerville42 merged commit 85575b9 into main Sep 9, 2026
10 checks passed
@Baskerville42
Baskerville42 deleted the dependabot/npm_and_yarn/svgo-4.1.0 branch September 9, 2026 20:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates javascript JavaScript and TypeScript ecosystem

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants