Skip to content

Security july 2026 - #26

Merged
jmgasper merged 4 commits into
developfrom
security_july_2026
Jul 20, 2026
Merged

Security july 2026#26
jmgasper merged 4 commits into
developfrom
security_july_2026

Conversation

@jmgasper

Copy link
Copy Markdown
Contributor

No description provided.

jmgasper added 4 commits July 20, 2026 12:19
Upgrade Node/OpenSSL for CVE-2026-48930 and CVE-2026-31789; update lodash for CVE-2026-4800, Joi for CVE-2026-48038, and Prisma/Hono for CVE-2026-29045.

Override axios CVE-2026-42043, form-data CVE-2026-12143, minimatch CVE-2026-27904, path-to-regexp CVE-2026-4867, qs CVE-2026-8723, and remove vulnerable runtime pnpm/npm tooling including GHSA-qrv3-253h-g69c.
Upgrade the production UUID dependency to 14.0.1, the first release not affected by predictable v1 identifiers. Inspector reports all earlier UUID releases as vulnerable.
@jmgasper
jmgasper merged commit 110f37a into develop Jul 20, 2026
3 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant