Skip to content

fix(deps): Bump transitive deps for medium security fixes#20679

Closed
chargome wants to merge 1 commit intodevelopfrom
fix/dependabot-medium-alerts
Closed

fix(deps): Bump transitive deps for medium security fixes#20679
chargome wants to merge 1 commit intodevelopfrom
fix/dependabot-medium-alerts

Conversation

@chargome
Copy link
Copy Markdown
Member

@chargome chargome commented May 5, 2026

Summary

  • Bumps postcss 8.5.6 → 8.5.14 (fixes XSS via unescaped </style>)
  • Bumps picomatch 2.3.1 → 2.3.2 (fixes method injection in POSIX character classes)
  • Bumps yaml 1.10.2 → 1.10.3 via cosmiconfig (fixes stack overflow via deeply nested collections)
  • Bumps @hono/node-server 1.19.10 → 2.0.1 (fixes middleware bypass via repeated slashes)
  • Fixes Dependabot alerts 1431, 1253, 1249, 1348

🤖 Generated with Claude Code

…ecurity fixes

- postcss 8.5.6 → 8.5.14 (fixes XSS via unescaped </style>)
- picomatch 2.3.1 → 2.3.2 (fixes method injection in POSIX classes)
- yaml 1.10.2 → 1.10.3 (fixes stack overflow via deep collections)
- @hono/node-server 1.19.10 → 2.0.1 (fixes middleware bypass via slashes)

Fixes Dependabot alerts 1431, 1253, 1249, 1348.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@chargome chargome self-assigned this May 5, 2026
"extends": "../../package.json"
}
}
} No newline at end of file
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

probably should not be checked in (this is some weird thing that yarn-update-dependency does for some reason... PRs are welcome xD)

@chargome chargome closed this May 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants