Skip to content

[pull] main from actions:main - #3

Merged
pull[bot] merged 1 commit into
Ditto190:mainfrom
actions:main
Aug 3, 2026
Merged

[pull] main from actions:main#3
pull[bot] merged 1 commit into
Ditto190:mainfrom
actions:main

Conversation

@pull

@pull pull Bot commented Aug 3, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )


Summary by cubic

Fixes high‑severity npm vulnerabilities by upgrading XML parsing dependencies and forcing a safe brace-expansion version across transitive deps. Rebuilds dist outputs and refreshes license metadata; npm audit now shows 0 vulnerabilities.

  • Dependencies
    • Upgrade fast-xml-parser to 5.10.1 (fixes GHSA-8r6m-32jq-jx6q).
    • Add override to force brace-expansion >= 5.0.8 (fixes GHSA-mh99-v99m-4gvg).
    • Refresh .licenses to match the new tree; remove legacy balanced-match, brace-expansion@1.x, and concat-map.
    • Rebuild dist/setup and dist/cache-save bundles.

Written for commit 8549b9f. Summary will update on new commits.

Review in cubic

- Upgrade fast-xml-parser to 5.10.1 (fixes GHSA-8r6m-32jq-jx6q)
- Add package.json override to force brace-expansion >=5.0.8 across
  all transitive dependencies (fixes GHSA-mh99-v99m-4gvg) without
  downgrading jest/ts-jest
- Refresh .licenses/npm cache to match updated dependency tree
- Rebuild dist/setup and dist/cache-save

npm audit now reports 0 vulnerabilities. Pre-existing test suite
failures (7 suites, ESM/jest teardown issue) verified unrelated to
this change - identical on unmodified main with node 24.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pull pull Bot locked and limited conversation to collaborators Aug 3, 2026
@pull pull Bot added the ⤵️ pull label Aug 3, 2026
@pull
pull Bot merged commit 8549b9f into Ditto190:main Aug 3, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant