Skip to content

chore(deps): npm audit fix - #44

Merged
some-git-user merged 1 commit into
mainfrom
audit-fix
Jul 27, 2026
Merged

chore(deps): npm audit fix#44
some-git-user merged 1 commit into
mainfrom
audit-fix

Conversation

@github-actions

@github-actions github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown

Automated dependency fixes produced by npm audit fix --omit=dev.

Security Summary (npm audit --omit=dev)

  • Before fix: critical=0, high=1, moderate=0, low=1, info=0 (npm exit code 1; expected when vulnerabilities are present)
  • After fix: critical=0, high=0, moderate=0, low=0, info=0

Top findings before fix (prod dependencies only):

  • [high] postcss: PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments (GHSA-6g55-p6wh-862q)
  • [high] postcss: PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure (GHSA-r28c-9q8g-f849)
  • [low] body-parser: body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement (GHSA-v422-hmwv-36x6)

Full audit JSON reports are attached as workflow artifacts (audit-before.json, audit-after.json).
Please review lockfile changes and run CI/tests before merging.

@some-git-user
some-git-user merged commit 0b9ba61 into main Jul 27, 2026
@some-git-user
some-git-user deleted the audit-fix branch July 27, 2026 20:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant