Skip to content

build(deps): bump less, nanoid and undici to fix DoS advisories - #2569

Merged
madhavilosetty-intel merged 1 commit into
mainfrom
fix/audit-less-nanoid-undici
Aug 26, 2026
Merged

build(deps): bump less, nanoid and undici to fix DoS advisories#2569
madhavilosetty-intel merged 1 commit into
mainfrom
fix/audit-less-nanoid-undici

Conversation

@madhavilosetty-intel

Copy link
Copy Markdown
Contributor

Applies npm audit fix. Resolves 3 high and 1 moderate dev-only advisories: GHSA-w3rx-r6r6-pgpr and GHSA-5p2g-fcmc-qvqq (image-size via less), GHSA-2v37-7h3g-55p8 (nanoid), and three undici advisories.

less 4.3.0 -> 4.9.0, nanoid 3.3.16 -> 3.3.18, undici 6.27.0 -> 6.28.0. Lockfile only; npm audit reports 0 vulnerabilities.

PR Checklist

  • Unit Tests have been added for new changes
  • API tests have been updated if applicable
  • All commented code has been removed
  • If you've added a dependency, you've ensured license is compatible with Apache 2.0 and clearly outlined the added dependency.

What are you changing?

Anything the reviewer should know when reviewing this PR?

If the there are associated PRs in other repositories, please link them here (i.e. device-management-toolkit/repo#365 )

Applies npm audit fix. Resolves 3 high and 1 moderate dev-only
advisories: GHSA-w3rx-r6r6-pgpr and GHSA-5p2g-fcmc-qvqq (image-size via
less), GHSA-2v37-7h3g-55p8 (nanoid), and three undici advisories.

less 4.3.0 -> 4.9.0, nanoid 3.3.16 -> 3.3.18, undici 6.27.0 -> 6.28.0.
Lockfile only; npm audit reports 0 vulnerabilities.
@madhavilosetty-intel
madhavilosetty-intel enabled auto-merge (squash) August 26, 2026 20:18
@madhavilosetty-intel
madhavilosetty-intel merged commit 7989142 into main Aug 26, 2026
7 checks passed
@madhavilosetty-intel
madhavilosetty-intel deleted the fix/audit-less-nanoid-undici branch August 26, 2026 20:19
@RosieAMT

Copy link
Copy Markdown

🎉 This PR is included in version 11.1.8 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants