Skip to content

fix: address open Dependabot alerts (Vite, Babel, Starlette, aiohttp)#122

Merged
cbullinger merged 1 commit into
mainfrom
security/dependabot-fixes-june-2026
Jun 18, 2026
Merged

fix: address open Dependabot alerts (Vite, Babel, Starlette, aiohttp)#122
cbullinger merged 1 commit into
mainfrom
security/dependabot-fixes-june-2026

Conversation

@cbullinger

@cbullinger cbullinger commented Jun 18, 2026

Copy link
Copy Markdown
Collaborator

Summary

Dependabot

Targets open alerts: #80#93 (aiohttp, Starlette, @babel/core, vite, launch-editor).

Test plan

  • npm install and npm test (unit) in frameworks/javascript/tanstack/app
  • uv pip compile / lockfile refresh for mflix/server/python-fastapi
  • CI green
  • Integration tests that spawn uvicorn + MongoDB (not run in this environment)

Made with Cursor

Upgrade Vite and npm overrides for launch-editor and @babel/core in the
TanStack sample, and raise aiohttp/starlette floors in mflix FastAPI so
pip-resolved pins include patched releases.

Co-authored-by: Cursor <cursoragent@cursor.com>

@krollins-mdb krollins-mdb left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks for the quick turnaround on this!

@cbullinger cbullinger merged commit 8b01c8c into main Jun 18, 2026
6 checks passed
@cbullinger cbullinger deleted the security/dependabot-fixes-june-2026 branch June 18, 2026 16:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants