Skip to content

build(deps): npm audit fix - #911

Open
github-actions[bot] wants to merge 1 commit into
masterfrom
npm-audit-fix-action/fix
Open

github-actions[bot] wants to merge 1 commit into
masterfrom
npm-audit-fix-action/fix

Conversation

@github-actions

@github-actions github-actions Bot commented May 9, 2026

Copy link
Copy Markdown
Contributor

This pull request fixes the vulnerable packages via npm 10.9.9.

Updated (4)
Package Version Source Detail
brace-expansion 1.1.141.1.21 github [High] brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups (ref)
brace-expansion (@typescript-eslint/typescript-estree/node_modules/brace-expansion) 2.1.02.1.7 github [High] brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups (ref)
fast-uri 3.0.13.1.7 github [High] fast-uri vulnerable to host confusion via literal backslash authority delimiter (ref)
js-yaml 4.1.14.3.2 github [High] JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases (ref)

Created by ybiquitous/npm-audit-fix-action

@github-actions github-actions Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code security Pull requests that address a security vulnerability labels May 9, 2026
@github-actions
github-actions Bot requested a review from timbru31 as a code owner May 9, 2026 03:21
@github-actions
github-actions Bot force-pushed the npm-audit-fix-action/fix branch 7 times, most recently from 44a53f9 to e4da65d Compare May 16, 2026 03:26
@github-actions
github-actions Bot force-pushed the npm-audit-fix-action/fix branch 7 times, most recently from 1d23077 to 673b646 Compare May 23, 2026 03:30
@github-actions
github-actions Bot force-pushed the npm-audit-fix-action/fix branch 7 times, most recently from adef52e to 3e64985 Compare May 30, 2026 03:38
@github-actions
github-actions Bot force-pushed the npm-audit-fix-action/fix branch 5 times, most recently from 8892458 to 4c4fa9f Compare June 4, 2026 04:16
@github-actions
github-actions Bot force-pushed the npm-audit-fix-action/fix branch 8 times, most recently from c658c97 to 57a9b33 Compare June 23, 2026 03:47
@github-actions
github-actions Bot force-pushed the npm-audit-fix-action/fix branch 7 times, most recently from d242bea to 8e924b1 Compare June 30, 2026 03:52
@github-actions
github-actions Bot force-pushed the npm-audit-fix-action/fix branch 8 times, most recently from 1642459 to d5d810e Compare July 8, 2026 02:52
@github-actions
github-actions Bot force-pushed the npm-audit-fix-action/fix branch 6 times, most recently from c39cf9c to 9abbf5c Compare July 14, 2026 02:39
Summary:
- Updated packages: 4
- Added packages: 0
- Removed packages: 0

Fixed vulnerabilities:
- brace-expansion: "brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups" (GHSA-3jxr-9vmj-r5cp)
- fast-uri: "fast-uri vulnerable to host confusion via literal backslash authority delimiter" (GHSA-v2hh-gcrm-f6hx)
- js-yaml: "JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases" (GHSA-h67p-54hq-rp68)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code security Pull requests that address a security vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant