Skip to content

fix: update vulnerable build dependencies - #27

Merged
AksharP5 merged 1 commit into
mainfrom
fix/update-vulnerable-build-dependencies
Aug 31, 2026
Merged

fix: update vulnerable build dependencies#27
AksharP5 merged 1 commit into
mainfrom
fix/update-vulnerable-build-dependencies

Conversation

@AksharP5

Copy link
Copy Markdown
Owner

npm audit found a high-severity Nano ID advisory and a moderate PostCSS advisory in Vite's transitive dependency tree.

This updates only the lockfile to Nano ID 3.3.18 and PostCSS 8.5.26, preserving the existing direct dependency versions.

Validated with a clean npm install, zero-vulnerability audit, the full repository check, production build, formatting check, and CLI package dry run.

@vercel

vercel Bot commented Aug 31, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
hyfrme Ready Ready Preview Aug 31, 2026 11:10pm

@AksharP5
AksharP5 merged commit 9af0132 into main Aug 31, 2026
3 checks passed
@AksharP5
AksharP5 deleted the fix/update-vulnerable-build-dependencies branch August 31, 2026 23:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant