Skip to content

chore(deps): update vulnerable transitive dependencies in the lockfile - #133

Merged
panz3r merged 2 commits into
mainfrom
chore/security-lockfile
Sep 29, 2026
Merged

panz3r merged 2 commits into
mainfrom
chore/security-lockfile

Conversation

@panz3r

@panz3r panz3r commented Sep 29, 2026

Copy link
Copy Markdown
Member

Resolves the 12 open Dependabot alerts by refreshing the lockfile:

  • brace-expansion 1.1.15 / 5.0.6 → 1.1.21 / 5.0.12 (via rimraf and browser-sync)
  • browserslist 4.28.2 → 4.29.2 (via babel)
  • immutable → 3.8.4, socket.io-parser → 4.2.7 (via browser-sync)
  • sharp 0.35.1 → 0.35.5: it was only installed as an auto-installed peer, so it is now an explicit devDependency of gulp-sharp. The peer range (>=0.33) is unchanged.

Consumers resolve these from upstream ranges, so no release is needed. Rebase after the gulp-sharp yoctocolors PR if both are open.

@panz3r
panz3r merged commit 0273b96 into main Sep 29, 2026
11 checks passed
@panz3r
panz3r deleted the chore/security-lockfile branch September 29, 2026 15:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant