Skip to content

Conversation

@DhanushPillay
Copy link

  • Updated axios from 1.11.0 to 1.13.2 (fixes CSRF and DoS vulnerabilities)
  • Updated playwright from 1.55.0 to 1.57.0 (fixes SSL certificate verification)
  • Updated js-yaml to 4.1.1 (fixes prototype pollution)
  • Updated jws from 3.2.2 to 3.2.3 (fixes HMAC signature verification)
  • Updated glob, body-parser, debug, koa, vite, and other packages

Ran 'npm audit fix' which reduced vulnerabilities from 73 to 68. Remaining 68 vulnerabilities are mostly in dev dependencies with no available fixes (requires infrastructure modernization).

- Updated axios from 1.11.0 to 1.13.2 (fixes CSRF and DoS vulnerabilities)
- Updated playwright from 1.55.0 to 1.57.0 (fixes SSL certificate verification)
- Updated js-yaml to 4.1.1 (fixes prototype pollution)
- Updated jws from 3.2.2 to 3.2.3 (fixes HMAC signature verification)
- Updated glob, body-parser, debug, koa, vite, and other packages

Ran 'npm audit fix' which reduced vulnerabilities from 73 to 68.
Remaining 68 vulnerabilities are mostly in dev dependencies with no
available fixes (requires infrastructure modernization).
@changeset-bot
Copy link

changeset-bot bot commented Dec 7, 2025

🦋 Changeset detected

Latest commit: 02f0e95

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@google-cla
Copy link

google-cla bot commented Dec 7, 2025

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants