Skip to content

Bump remaining vulnerable dev dependencies#260

Merged
huntie merged 1 commit into
mainfrom
nc/dependency-bumps-remaining
Jun 10, 2026
Merged

Bump remaining vulnerable dev dependencies#260
huntie merged 1 commit into
mainfrom
nc/dependency-bumps-remaining

Conversation

@cortinico

@cortinico cortinico commented Jun 4, 2026

Copy link
Copy Markdown

Summary:

  • Bump Rollup to a fixed 4.59.x-compatible version
  • Update the lockfile for qs, flatted, follow-redirects, and basic-ftp fixed versions
  • Add a scoped Mocha override so its minimatch 4.x dependency resolves to 4.2.5

Verification:

  • npm run lint
  • npm run prebuild
  • npm run build

@meta-cla meta-cla Bot added the cla signed label Jun 4, 2026
@cortinico cortinico requested a review from huntie June 4, 2026 15:20
@cortinico cortinico marked this pull request as ready for review June 4, 2026 15:20
@huntie huntie merged commit e06f16d into main Jun 10, 2026
5 checks passed
@huntie huntie deleted the nc/dependency-bumps-remaining branch June 10, 2026 13:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants