Skip to content

fix: apply audit fixes

894e4af
Select commit
Loading
Failed to load commit list.
Open

fix: Security updates #89

fix: apply audit fixes
894e4af
Select commit
Loading
Failed to load commit list.
StepSecurity Actions Security / StepSecurity Required Checks succeeded Apr 13, 2026 in 0s

StepSecurity Required Checks

Finished StepSecurity Required Checks

  • NPM Compromised Packages Check - Checks for compromised npm package versions in the PR
  • NPM Package Cooldown Check - Fails if any package version in the PR was released within the configured cooldown period, helping to avoid brand-new (and potentially unreviewed or malicious) releases
  • Pwn Request Vulnerabilities Check - Checks for Pwn Request vulnerabilities in the PR via risky triggers
  • Script Injection Check - Checks for script injection vulnerabilities in the PR

Details

✅ Script Injection Vulnerabilities Check

No Script Injection vulnerabilities found in this PR.

✅ Pwn Request Vulnerabilities Check

No Pwn Request vulnerabilities found in this PR.

✅ NPM Package Cooldown Check

No npm package upgrades to recent releases found in current PR.

The following npm packages are inspected in current PR

Package Name Previous Version Current Version file Current Version Release Date
axios 1.13.5 1.15.0 package-lock.json 2026-04-08T16:09:38Z
proxy-from-env 1.1.0 2.1.0 package-lock.json 2026-03-14T18:32:47Z
✅ NPM Compromised Packages Check

No Compromised npm packages are added in current PR.

⏲️ History

Previous invocation results of same check:

✅ Script Injection Vulnerabilities Check

No Script Injection vulnerabilities found in this PR.

✅ Pwn Request Vulnerabilities Check

No Pwn Request vulnerabilities found in this PR.

✅ NPM Package Cooldown Check

No npm package upgrades to recent releases found in current PR.

The following npm packages are inspected in current PR

Package Name Previous Version Current Version file Current Version Release Date
axios 1.13.5 1.15.0 package-lock.json 2026-04-08T16:09:38Z
proxy-from-env 1.1.0 2.1.0 package-lock.json 2026-03-14T18:32:47Z
✅ NPM Compromised Packages Check

No Compromised npm packages are added in current PR.