Skip to content

deps: fix critical npm vulnerabilities - #976

Merged
Liangying.Wei (vicancy) merged 3 commits into
mainfrom
vicancy/fix-critical-npm-alerts
Aug 17, 2026
Merged

deps: fix critical npm vulnerabilities#976
Liangying.Wei (vicancy) merged 3 commits into
mainfrom
vicancy/fix-critical-npm-alerts

Conversation

@vicancy

@vicancy Liangying.Wei (vicancy) commented Aug 14, 2026

Copy link
Copy Markdown
Member

Summary

Validation

  • Yarn frozen-lockfile install
  • awps-tunnel client lint
  • awps-tunnel client production build

Pin shell-quote 1.8.4 and websocket-driver 0.7.5 across the root workspace and standalone tunnel client lockfile.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 6897cee9-248f-47db-a739-ab3a51b94527
Address GHSA-395f-4hp3-45gv reported by Dependency Review after the initial critical fix.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 6897cee9-248f-47db-a739-ab3a51b94527
@vicancy
Liangying.Wei (vicancy) enabled auto-merge (squash) August 17, 2026 01:51
@vicancy
Liangying.Wei (vicancy) merged commit 4c62daa into main Aug 17, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants