Skip to content

[agent] chore(deps): bump webpack to ^5.104.1 in sbom-tools#721

Open
github-actions[bot] wants to merge 1 commit intomainfrom
fix/dependabot-webpack-cve-0f4eeb447b2202fe
Open

[agent] chore(deps): bump webpack to ^5.104.1 in sbom-tools#721
github-actions[bot] wants to merge 1 commit intomainfrom
fix/dependabot-webpack-cve-0f4eeb447b2202fe

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

Bumps the direct devDependency webpack in packages/sbom-tools/package.json from ^5.82.0 to ^5.104.1. npm resolved it to 5.106.2.

Security alerts addressed

# CVE GHSA Severity Fixed in
#35 CVE-2024-43788 GHSA-4vvj-4cpr-p986 medium 5.94.0
#138 CVE-2025-68458 GHSA-8fgc-7cc6-rx7x low 5.104.1
#139 CVE-2025-68157 GHSA-38r7-794h-5758 low 5.104.0

Changes

  • packages/sbom-tools/package.json: "webpack": "^5.82.0""webpack": "^5.104.1"
  • package-lock.json: updated to resolve webpack to 5.106.2

Generated by Dependabot remediation agent · ● 477.9K ·

Addresses three Dependabot security alerts for webpack (transitive
dependency pulled in by packages/sbom-tools):

- #35  CVE-2024-43788 / GHSA-4vvj-4cpr-p986 (medium) – fixed in 5.94.0
- #138 CVE-2025-68458 / GHSA-8fgc-7cc6-rx7x (low)   – fixed in 5.104.1
- #139 CVE-2025-68157 / GHSA-38r7-794h-5758 (low)   – fixed in 5.104.0

Bumped the direct devDependency range from ^5.82.0 to ^5.104.1 in
packages/sbom-tools/package.json. npm resolved it to 5.106.2.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@nirinchev nirinchev closed this Apr 30, 2026
@nirinchev nirinchev reopened this Apr 30, 2026
@nirinchev nirinchev marked this pull request as ready for review April 30, 2026 13:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant