Skip to content

chore(deps): npm audit fix for js-yaml and qs (dev-only) - #295

Merged
forcingfx merged 1 commit into
mainfrom
chore/audit-fix-dev-deps
Sep 9, 2026
Merged

forcingfx merged 1 commit into
mainfrom
chore/audit-fix-dev-deps

Conversation

@forcingfx

Copy link
Copy Markdown
Owner

Lockfile-only npm audit fix clearing the two remaining dev-dependency advisories: js-yaml (high) and qs (moderate). The production audit gate was already green; npm audit now reports 0 vulnerabilities.

Verified locally: node scripts/audit-gate.mjs passes, npm test 3963 passed.

🤖 Generated with Claude Code

https://claude.ai/code/session_01GQoLHbPfaTCHvPuaoqGZeJ

Clears the two remaining npm audit findings, both in devDependencies:
js-yaml (high, CPU use via empty merge sources) and qs (moderate,
array-limit bypass). Lockfile only; the production audit gate was already
green, so this is hygiene rather than a fix to a shipped path.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GQoLHbPfaTCHvPuaoqGZeJ
@vercel

vercel Bot commented Sep 9, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
feedzero Ready Ready Preview Sep 9, 2026 8:20pm UTC

Request Review

@forcingfx
forcingfx enabled auto-merge (squash) September 9, 2026 20:19
@forcingfx
forcingfx merged commit 01ee55b into main Sep 9, 2026
17 checks passed

This branch was successfully deployed

1 active deployment
Preview 1e7b6410 Deployed Sep 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant