Skip to content

Conversation

@mrkimani-ndegwa
Copy link

Upgrade multiple dependencies to address security vulnerabilities:

  • word-wrap: 1.2.3 → 1.2.5
  • semver: 6.3.0 → 6.3.1
  • decode-uri-component: 0.2.0 → 0.2.2
  • shelljs: 0.8.4 → 0.8.5

These upgrades fix 89 security vulnerabilities:

  • 81 High-severity vulnerabilities
  • 8 Moderate-severity vulnerabilities

Total vulnerabilities reduced from 274 to 185.

Added yarn resolutions to force upgrade of transitive dependencies. Verified all packages build successfully.

Addresses security PRs: #126, #125, #122, #112, #111, #109, #108, #107, #105

Upgrade multiple dependencies to address security vulnerabilities:

- word-wrap: 1.2.3 → 1.2.5
- semver: 6.3.0 → 6.3.1
- decode-uri-component: 0.2.0 → 0.2.2
- shelljs: 0.8.4 → 0.8.5

These upgrades fix 89 security vulnerabilities:
- 81 High-severity vulnerabilities
- 8 Moderate-severity vulnerabilities

Total vulnerabilities reduced from 274 to 185.

Added yarn resolutions to force upgrade of transitive dependencies.
Verified all packages build successfully.

Addresses security PRs: #126, #125, #122, #112, #111, #109, #108, #107, #105
@Seismic-Security-Service
Copy link

Seismic-Security-Service commented Nov 3, 2025

Snyk checks have failed. 3 issues have been found so far.

Status Scanner Critical High Medium Low Total (3)
Open Source Security 0 3 0 0 3 issues
Licenses 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@mrkimani-ndegwa mrkimani-ndegwa marked this pull request as ready for review November 10, 2025 15:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants