Skip to content

fix: patch vulnerabilities and bump outdated dependencies - #7556

Open
waldekmastykarz wants to merge 2 commits into
pnp:mainfrom
waldekmastykarz:waldekmastykarz-weekly-deps-bump-00a
Open

fix: patch vulnerabilities and bump outdated dependencies#7556
waldekmastykarz wants to merge 2 commits into
pnp:mainfrom
waldekmastykarz:waldekmastykarz-weekly-deps-bump-00a

Conversation

@waldekmastykarz

Copy link
Copy Markdown
Member

Vulnerability Patch Summary

Vulnerabilities fixed: 37 → 0

Packages patched

Direct:

  • axios: ^1.16.1 → ^1.19.0 (fixes 11 high severity vulnerabilities)
  • adm-zip: ^0.5.17 → ^0.6.0 (⚠️ major version bump, fixes high severity memory allocation vuln)
  • applicationinsights: ^3.14.0 → ^3.16.0

Outdated packages updated (semver-compatible):

  • @azure/msal-common: 16.6.2 → 16.13.0
  • @azure/msal-node: 5.2.2 → 5.6.0
  • @inquirer/confirm: 6.1.0 → 6.2.0
  • @inquirer/input: 5.1.0 → 5.1.3
  • @inquirer/select: 5.2.0 → 5.2.2
  • @types/node: 24.12.4 → 24.13.3
  • @types/semver: 7.7.1 → 7.8.0
  • @typescript-eslint/eslint-plugin: 8.60.0 → 8.67.0
  • @typescript-eslint/parser: 8.60.1 → 8.67.0
  • @xmldom/xmldom: 0.9.10 → 0.9.12
  • clipboardy: 5.3.1 → 5.3.2
  • csv-stringify: 6.7.0 → 6.8.3
  • eslint: 10.4.0 → 10.9.0
  • globals: 17.6.0 → 17.11.0
  • mocha: 11.7.6 → 11.8.0
  • open: 11.0.0 → 11.0.1
  • semver: 7.8.1 → 7.8.5
  • sinon: 22.0.0 → 22.1.0
  • tsc-watch: 7.2.0 → 7.2.1
  • uuid: 14.0.0 → 14.0.2

Transitive (via overrides):

  • @opentelemetry/core: → 2.10.0 (fixes moderate baggage propagation vuln)
  • @opentelemetry/propagator-jaeger: → >=2.10.0 (fixes high DoS vuln)
  • protobufjs: 7.6.0 → 7.6.5 (fixes 3 high severity vulnerabilities)
  • @opentelemetry/sdk-node / @opentelemetry/exporter-prometheus: → 0.220.0

Remaining vulnerabilities: 0 🎉

Notes

…kages

Updates:
- axios: ^1.16.1 -> ^1.19.0 (fixes 11 high severity vulnerabilities)
- adm-zip: ^0.5.17 -> ^0.6.0 (fixes high severity memory allocation vuln)
- applicationinsights: ^3.14.0 -> ^3.16.0 (updates transitive OpenTelemetry deps)
- @opentelemetry/core override: 2.10.0 (fixes moderate baggage propagation vuln)
- @opentelemetry/propagator-jaeger override: >=2.10.0 (fixes high DoS vuln)
- protobufjs override: 7.6.5 (fixes 3 high severity vulnerabilities)
- Updates all semver-compatible outdated packages

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant