Skip to content

fix(deps): resolve npm audit and Dependabot vulnerabilities - #159

Merged
gkrajniak merged 1 commit into
mainfrom
chore/vuls-07102026
Oct 7, 2026
Merged

gkrajniak merged 1 commit into
mainfrom
chore/vuls-07102026

Conversation

@gkrajniak

Copy link
Copy Markdown
Member

Summary

Resolves the open Dependabot alerts and the npm audit findings in all three packages. After the change, npm audit reports 0 vulnerabilities in eslint-config-typescript, config-prettier and gha-cache.

eslint-config-typescript (lockfile update, npm audit fix)

  • brace-expansion 1.1.18 → 1.1.21, 2.1.4 → 5.0.12
  • @angular/cli 22.1.4 → 22.2.2 (transitive), which replaces @modelcontextprotocol/sdk 1.30.0 with @modelcontextprotocol/server 2.3.1 and drops the express stack it pulled in (proxy-addr 2.0.7, ip-address 10.5.0)
  • typescript-eslint 8.24.1 → 8.71.1, which no longer pulls in fast-glob/micromatch/braces 3.0.3

config-prettier (lockfile update, npm audit fix)

  • brace-expansion 2.1.4 → 2.1.7

gha-cache (override)

  • undici 6.28.0 → 6.28.1: the existing overrides entry pinned the vulnerable 6.28.0; raised to the first patched version

Verification

npm ci, npm install, build and test pass in every package. The packages have no real tests (test scripts are stubs).

## Summary

Resolves the open Dependabot alerts and the `npm audit` findings in all three packages. After the change, `npm audit` reports 0 vulnerabilities in `eslint-config-typescript`, `config-prettier` and `gha-cache`.

## eslint-config-typescript (lockfile update, `npm audit fix`)

- brace-expansion 1.1.18 → 1.1.21, 2.1.4 → 5.0.12
- @angular/cli 22.1.4 → 22.2.2 (transitive), which replaces @modelcontextprotocol/sdk 1.30.0 with @modelcontextprotocol/server 2.3.1 and drops the express stack it pulled in (proxy-addr 2.0.7, ip-address 10.5.0)
- typescript-eslint 8.24.1 → 8.71.1, which no longer pulls in fast-glob/micromatch/braces 3.0.3

## config-prettier (lockfile update, `npm audit fix`)

- brace-expansion 2.1.4 → 2.1.7

## gha-cache (override)

- undici 6.28.0 → 6.28.1: the existing `overrides` entry pinned the vulnerable 6.28.0; raised to the first patched version

## Verification

`npm ci`, `npm install`, `build` and `test` pass in every package. The packages have no real tests (`test` scripts are stubs).

On-behalf-of: @SAP grzegorz.krajniak@sap.com
Signed-off-by: gkrajniak <gkrajniak@gmail.com>
@gkrajniak gkrajniak self-assigned this Oct 7, 2026
@gkrajniak
gkrajniak requested a review from a team as a code owner October 7, 2026 08:17
@coderabbitai

coderabbitai Bot commented Oct 7, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: b254341f-a160-4659-9ffd-3f45be5ae4e9
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gkrajniak
gkrajniak enabled auto-merge (squash) October 7, 2026 08:30
@gkrajniak
gkrajniak disabled auto-merge October 7, 2026 09:46
@gkrajniak
gkrajniak enabled auto-merge (squash) October 7, 2026 09:46
@gkrajniak
gkrajniak disabled auto-merge October 7, 2026 09:55
@gkrajniak
gkrajniak merged commit 0d1aa30 into main Oct 7, 2026
14 of 15 checks passed
@gkrajniak
gkrajniak deleted the chore/vuls-07102026 branch October 7, 2026 09:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants