Skip to content

deps: update vulnerable transitive dependencies - #9872

Open
martinrrm wants to merge 3 commits into
release/v11from
deps/vulnerable-transitives-v11
Open

deps: update vulnerable transitive dependencies#9872
martinrrm wants to merge 3 commits into
release/v11from
deps/vulnerable-transitives-v11

Conversation

@martinrrm

Copy link
Copy Markdown
Contributor

Summary

  • updates bundled brace-expansion from 5.0.7 to 5.0.9
  • updates bundled ip-address from 10.2.0 to 10.5.0
  • updates bundled undici from 6.27.0 to 6.28.0
  • refreshes nested development copies of brace-expansion to 1.1.18

The production audit now reports only the separate tar advisory addressed by #9842.

Testing

  • node . run dependencies --ignore-scripts
  • node . ls brace-expansion ip-address undici --all --omit=dev
  • node . audit --omit=dev --json
  • TMPDIR=$PWD/.tmp node . test --ignore-scripts

@martinrrm
martinrrm requested review from a team as code owners August 13, 2026 21:22
@martinrrm
martinrrm force-pushed the deps/vulnerable-transitives-v11 branch from 49bbbfb to a9da8b2 Compare August 18, 2026 21:41
martinrrm and others added 3 commits August 18, 2026 15:01
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3f0ccf56-34fa-491a-9f58-ad4c6de7cd02
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3f0ccf56-34fa-491a-9f58-ad4c6de7cd02
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3f0ccf56-34fa-491a-9f58-ad4c6de7cd02
@martinrrm
martinrrm force-pushed the deps/vulnerable-transitives-v11 branch from a9da8b2 to 8e3bc8a Compare August 18, 2026 22:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant