Skip to content

Upgrade vulnerable direct dependencies (npm audit: 0 vulnerabilities) - #1160

Merged
alexmontesg merged 2 commits into
mainfrom
dependency/GH-1147-upgrade-vulnerable-direct
Sep 3, 2026
Merged

alexmontesg merged 2 commits into
mainfrom
dependency/GH-1147-upgrade-vulnerable-direct

Conversation

@alexmontesg

Copy link
Copy Markdown
Contributor

Closes #1147

@alexmontesg
alexmontesg marked this pull request as ready for review September 3, 2026 08:03
@alexmontesg alexmontesg self-assigned this Sep 3, 2026
@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

🚀 Release Preview Success

You are going to release the version patch with the following changes:

5.2.3 - 2026-09-03

Fixed

  • #1147 Remove false positive vulnerabilities on template

💡 Merge Strategy: Squash and Merge

Remember to use the 'Squash and Merge' strategy to merge this Pull Request (dependency/GH-1147-upgrade-vulnerable-directmain).

@alexmontesg
alexmontesg requested a review from jesusmpc September 3, 2026 08:08
@alexmontesg alexmontesg added skip-release Skips the release creation and removed release-type/patch labels Sep 3, 2026
@alexmontesg
alexmontesg force-pushed the dependency/GH-1147-upgrade-vulnerable-direct branch from a585bff to 9fe1ef0 Compare September 3, 2026 08:21
Signed-off-by: Alejandro Montes <alejandromogarcia@ext.inditex.com>
next@14.2.32 and sharp@0.33.5 in the frontend template flagged known
CVEs in dependency scans, but the vulnerable code paths aren't
reachable from the scaffolded template. Bump to next@16.3.4,
eslint-config-next@16.3.4 and sharp@0.35.4 to clear the false
positives from vulnerability reports.

Closes #1147
@alexmontesg
alexmontesg force-pushed the dependency/GH-1147-upgrade-vulnerable-direct branch from 9fe1ef0 to e789a58 Compare September 3, 2026 09:32
@sonarqubecloud

sonarqubecloud Bot commented Sep 3, 2026

Copy link
Copy Markdown

@alexmontesg
alexmontesg merged commit 5c5c1d5 into main Sep 3, 2026
19 checks passed
@alexmontesg
alexmontesg deleted the dependency/GH-1147-upgrade-vulnerable-direct branch September 3, 2026 09:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip-release Skips the release creation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Upgrade vulnerable direct dependencies (npm audit: 0 vulnerabilities)

2 participants