Skip to content

fix(deps): resolve npm audit and Dependabot vulnerabilities - #171

Open
gkrajniak wants to merge 1 commit into
mainfrom
chore/vuls-16092026
Open

gkrajniak wants to merge 1 commit into
mainfrom
chore/vuls-16092026

Conversation

@gkrajniak

Copy link
Copy Markdown
Member

Frontend lockfile updates (npm audit fix):

  • @angular-devkit/build-angular 22.1.4 → 22.1.8, which moves less
    4.6.7 → 4.9.0 and drops the vulnerable image-size 0.5.5
  • fast-uri 3.1.5 → 3.1.8
  • js-yaml 4.3.1 → 4.3.2
  • hono 4.13.2 → 4.13.8
  • express 4.22.2 → 4.22.3, body-parser 1.20.6 → 1.20.8
  • qs 6.15.3 → 6.16.0

Verified: npm audit reports 0 vulnerabilities in the root and frontend
workspaces; the frontend build passes (the test script is a stub).

🤖 Generated with Claude Code

Frontend lockfile updates (`npm audit fix`):
- @angular-devkit/build-angular 22.1.4 → 22.1.8, which moves less
  4.6.7 → 4.9.0 and drops the vulnerable image-size 0.5.5
- fast-uri 3.1.5 → 3.1.8
- js-yaml 4.3.1 → 4.3.2
- hono 4.13.2 → 4.13.8
- express 4.22.2 → 4.22.3, body-parser 1.20.6 → 1.20.8
- qs 6.15.3 → 6.16.0

Verified: npm audit reports 0 vulnerabilities in the root and frontend
workspaces; the frontend build passes (the `test` script is a stub).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: gkrajniak <gkrajniak@gmail.com>
@gkrajniak gkrajniak self-assigned this Sep 16, 2026
@coderabbitai

coderabbitai Bot commented Sep 16, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 95b8b31c-5132-4baa-b6ba-fed3c8ed46f9


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added the fix label Sep 16, 2026
@gkrajniak gkrajniak moved this to In review in OpenMFP Development Sep 16, 2026
@gkrajniak
gkrajniak enabled auto-merge (squash) September 16, 2026 11:29
@gkrajniak
gkrajniak disabled auto-merge September 16, 2026 11:30
@gkrajniak
gkrajniak enabled auto-merge (squash) September 16, 2026 11:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

Status: In review

Development

Successfully merging this pull request may close these issues.

2 participants