Skip to content

fix(deps): patch transitive npm advisories via audit fix - #291

Merged
kauereinbold merged 1 commit into
mainfrom
feature/deps-security-audit-fix
Jul 8, 2026
Merged

fix(deps): patch transitive npm advisories via audit fix#291
kauereinbold merged 1 commit into
mainfrom
feature/deps-security-audit-fix

Conversation

@kauereinbold

Copy link
Copy Markdown
Owner

Lockfile-only bumps to patched versions across blockchain, react app, cypress: form-data 4.0.6, minimatch 9.0.9, lodash 4.18.1, js-yaml 4.3.0, @babel/core 7.29.7, undici 6.27.0, postcss 8.x. No package.json changes.

Closes the majority of the 19 open Dependabot alerts. Residual dev-only transitive (postcss 7 via madge, undici 5.x via hardhat tooling) require breaking major bumps and are deferred.

Bumps transitive-only lockfile entries to patched versions across
blockchain, react app, and cypress: form-data 4.0.6, minimatch 9.0.9,
lodash 4.18.1, js-yaml 4.3.0, @babel/core 7.29.7, undici 6.27.0,
postcss 8.x. No package.json / direct-dependency changes.

Residual dev-only transitive (postcss 7 via madge, undici 5.x via
hardhat tooling) need breaking major bumps; deferred.
@kauereinbold
kauereinbold merged commit 9975954 into main Jul 8, 2026
5 of 7 checks passed
@kauereinbold
kauereinbold deleted the feature/deps-security-audit-fix branch July 8, 2026 12:26
kauereinbold added a commit that referenced this pull request Jul 10, 2026
Bumps transitive-only lockfile entries to patched versions across
blockchain, react app, and cypress: form-data 4.0.6, minimatch 9.0.9,
lodash 4.18.1, js-yaml 4.3.0, @babel/core 7.29.7, undici 6.27.0,
postcss 8.x. No package.json / direct-dependency changes.

Residual dev-only transitive (postcss 7 via madge, undici 5.x via
hardhat tooling) need breaking major bumps; deferred.
kauereinbold added a commit that referenced this pull request Jul 10, 2026
Bumps transitive-only lockfile entries to patched versions across
blockchain, react app, and cypress: form-data 4.0.6, minimatch 9.0.9,
lodash 4.18.1, js-yaml 4.3.0, @babel/core 7.29.7, undici 6.27.0,
postcss 8.x. No package.json / direct-dependency changes.

Residual dev-only transitive (postcss 7 via madge, undici 5.x via
hardhat tooling) need breaking major bumps; deferred.
kauereinbold added a commit that referenced this pull request Aug 9, 2026
Bumps transitive-only lockfile entries to patched versions across
blockchain, react app, and cypress: form-data 4.0.6, minimatch 9.0.9,
lodash 4.18.1, js-yaml 4.3.0, @babel/core 7.29.7, undici 6.27.0,
postcss 8.x. No package.json / direct-dependency changes.

Residual dev-only transitive (postcss 7 via madge, undici 5.x via
hardhat tooling) need breaking major bumps; deferred.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant