Skip to content

chore(security): clear Dependabot critical/high npm advisories - #68

Merged
thomasrockhu-codecov merged 1 commit into
mainfrom
th/dependabot-cve-form-data
Aug 11, 2026
Merged

chore(security): clear Dependabot critical/high npm advisories#68
thomasrockhu-codecov merged 1 commit into
mainfrom
th/dependabot-cve-form-data

Conversation

@thomasrockhu-codecov

Copy link
Copy Markdown
Contributor

Summary

  • Bump express and add npm overrides for form-data, js-yaml, brace-expansion, path-to-regexp, minimatch, cross-spawn, and picomatch.
  • Clears Dependabot critical/high alerts (projected until merge).

Test plan

  • CI passes on this branch
  • After merge, Dependabot critical/high count drops to 0

Bump express and add npm overrides for form-data, js-yaml, brace-expansion, path-to-regexp, minimatch, cross-spawn, and picomatch (including abandoned request transitive form-data).
@thomasrockhu-codecov
thomasrockhu-codecov requested a review from a team as a code owner August 7, 2026 22:45
@codecov

codecov Bot commented Aug 7, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 70.00%. Comparing base (36f366f) to head (8bc7c79).

Additional details and impacted files
@@           Coverage Diff           @@
##             main      #68   +/-   ##
=======================================
  Coverage   70.00%   70.00%           
=======================================
  Files           1        1           
  Lines          10       10           
  Branches        3        3           
=======================================
  Hits            7        7           
  Misses          3        3           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

@thomasrockhu-codecov
thomasrockhu-codecov merged commit e54690c into main Aug 11, 2026
7 checks passed
@thomasrockhu-codecov
thomasrockhu-codecov deleted the th/dependabot-cve-form-data branch August 11, 2026 21:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant