Skip to content

fix(deps): remediate open security alerts - #881

Merged
BYK merged 1 commit into
masterfrom
fix/dependabot-alerts
Sep 25, 2026
Merged

BYK merged 1 commit into
masterfrom
fix/dependabot-alerts

Conversation

@BYK

@BYK BYK commented Sep 25, 2026

Copy link
Copy Markdown
Member

Summary

  • Add root pnpm overrides for patched baseline-browser-mapping, browserslist, fast-uri, @humanfs/node, and nanoid releases.
  • Update docs overrides for js-yaml and postcss-selector-parser.
  • Regenerate both independent lockfiles.

Verification

  • pnpm install --frozen-lockfile in root and docs
  • pnpm audit in root and docs: no known vulnerabilities
  • pnpm format:check
  • pnpm typecheck
  • pnpm lint (0 errors; seven pre-existing warnings)
  • pnpm test -- --printConsoleTrace
  • pnpm build in root and docs

The lockfiles contain no vulnerable alert versions.

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor
PR Preview Action v1.8.1
Preview removed because the pull request was closed.
2026-09-25 22:02 UTC

@BYK
BYK merged commit bba2a96 into master Sep 25, 2026
23 checks passed
@BYK
BYK deleted the fix/dependabot-alerts branch September 25, 2026 22:02

This branch was successfully deployed

1 active deployment
false — 43c4477b Deployed Sep 25, 2026 by BYK via Build #2938
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant