Skip to content

Update dependencies to resolve Dependabot alerts - #14818

Merged
Sean McManus (sean-mcmanus) merged 1 commit into
mainfrom
seanmcm/devbox2-wsl/agent257/dependabot-security-updates
Oct 5, 2026
Merged

Sean McManus (sean-mcmanus) merged 1 commit into
mainfrom
seanmcm/devbox2-wsl/agent257/dependabot-security-updates

Conversation

@sean-mcmanus

Copy link
Copy Markdown
Contributor

Summary

Update the Actions, Extension, and Themes dependency lockfiles to remediate all 28 currently open Dependabot alerts for Axios, Undici, ip-address, and brace-expansion. Preserve the existing manifest ranges and each brace-expansion major-version family.

  • Axios: 1.18.1 → 1.20.0.
  • Undici: 6.28.0 → 6.29.0.
  • ip-address: 10.3.1 → 10.7.2.
  • brace-expansion: 1.1.18 → 1.1.21, 2.1.4 → 2.1.7, and 5.0.9 → 5.0.12.

No manifest, release-version, or changelog changes.

This PR was investigated and created by GitHub Copilot (in VS Code). Any message starting with ✨Copilot: was sent by Copilot.

Validation

  • All 28 alert ranges reproduce on the target baseline and exclude the updated lockfile versions.
  • Clean Actions and Themes npm installs; frozen Extension Yarn install.
  • Actions typecheck and 39 tests passed.
  • Extension build, lint, 221 unit tests, 21 acquisition tests, and 2 lockfile tests passed.
  • Themes audit: 0 vulnerabilities.
  • Dependency-graph, formatting, and whitespace checks passed.

Existing audit finding

Actions still reports the unrelated, pre-existing braces advisory GHSA-vfj7-8cjw-p6xm through its Mocha/chokidar development dependency tree. That is a different package from brace-expansion and is unchanged by this PR.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The scoped lockfile updates preserve dependency compatibility, with no unresolved review findings.

Copilot wasn't able to review any files in this pull request.

Files not reviewed (2)
  • .github/actions/package-lock.json: Generated file
  • Themes/package-lock.json: Generated file

@sean-mcmanus
Sean McManus (sean-mcmanus) marked this pull request as ready for review October 5, 2026 22:39
@sean-mcmanus
Sean McManus (sean-mcmanus) requested a review from a team as a code owner October 5, 2026 22:40
@sean-mcmanus
Sean McManus (sean-mcmanus) merged commit 8377b1c into main Oct 5, 2026
8 checks passed
@sean-mcmanus
Sean McManus (sean-mcmanus) deleted the seanmcm/devbox2-wsl/agent257/dependabot-security-updates branch October 5, 2026 23:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants