Skip to content

Address security vulnerabilities in core dependencies - #151

Merged
RumenDamyanov merged 1 commit into
masterfrom
security/fix-dependabot-alert-46-53
Jul 12, 2026
Merged

Address security vulnerabilities in core dependencies#151
RumenDamyanov merged 1 commit into
masterfrom
security/fix-dependabot-alert-46-53

Conversation

@RumenDamyanov

Copy link
Copy Markdown
Owner

This PR addresses security vulnerabilities identified across several core project dependencies. It updates @babel/core, brace-expansion, and uuid to patched versions to resolve potential security risks.

Changes

Impact

These updates are non-breaking and are intended strictly for security hardening.

…d uuid

- Update @babel/core to fix arbitrary file read (GHSA-4x5r-pxfx-6jf8)
- Update brace-expansion to fix DoS vulnerabilities (GHSA-f886-m6hf-6m8v, GHSA-jxxr-4gwj-5jf2)
- Update uuid to fix buffer bounds check (GHSA-w5hq-g745-h8pq)
@RumenDamyanov RumenDamyanov self-assigned this Jul 12, 2026
Copilot AI review requested due to automatic review settings July 12, 2026 08:29

This comment was marked as low quality.

@RumenDamyanov
RumenDamyanov merged commit 97f49f3 into master Jul 12, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants