Skip to content

Bump dependencies to resolve known vulnerabilities (v5.3.3)#230

Merged
Keith-wright merged 1 commit intomasterfrom
security/dependabot-consolidation
Mar 18, 2026
Merged

Bump dependencies to resolve known vulnerabilities (v5.3.3)#230
Keith-wright merged 1 commit intomasterfrom
security/dependabot-consolidation

Conversation

@Keith-wright
Copy link
Contributor

Summary

Consolidates and supersedes dependabot PRs #210, #211, #215, #216, #218, #220, #221, #227, #228, #229.

Changes

package.json

Direct dependency bumps:

  • node-fetch: ^2.6.1^2.7.0
  • express (devDep): ^4.17.1^4.22.1
  • eslint (devDep): ^7.11.0^7.32.0
  • mocha (devDep): ^7.2.0^9.2.2

Transitive dependency overrides (new):

  • cipher-base^1.0.6
  • cookie^0.7.1
  • elliptic^6.6.1
  • form-data^3.0.4
  • lodash^4.17.23
  • pbkdf2^3.1.5
  • qs^6.14.0
  • sha.js^2.4.12
  • tar^6.2.1

CHANGELOG.md

  • Version bump: 5.3.25.3.3

Result

  • Vulnerabilities reduced from 52 → 37 (remaining are in the webpack 4.x ecosystem and require a major version upgrade)

Supersedes

#210, #211, #215, #216, #218, #220, #221, #227, #228, #229

Direct dep bumps:
- node-fetch: ^2.6.1 -> ^2.7.0
- express: ^4.17.1 -> ^4.22.1 (devDep)
- eslint: ^7.11.0 -> ^7.32.0 (devDep)
- mocha: ^7.2.0 -> ^9.2.2 (devDep)

Transitive dep overrides:
- cipher-base, cookie, elliptic, form-data, lodash,
  pbkdf2, qs, sha.js, tar
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants