Skip to content

[Vulnerability][Patches] Apply patch to vulnerable dependencies#177

Merged
juanmrad merged 2 commits intomainfrom
vulnerability-patch-upgrades
Apr 6, 2026
Merged

[Vulnerability][Patches] Apply patch to vulnerable dependencies#177
juanmrad merged 2 commits intomainfrom
vulnerability-patch-upgrades

Conversation

@juanmrad
Copy link
Copy Markdown
Member

@juanmrad juanmrad commented Apr 4, 2026

Context & Requests for Reviewers

Does safe vulnerability package updates to packages that require no code changes, it resolve Dependabot alerts by updating lockfile resolutions and bumping package.json minimums for lodash, kysely, sequelize, and lint-staged

All other lockfile updates are safe, non-breaking transitive dependency resolutions via npm update / npm audit fix and verified running tests and locally.

@juanmrad juanmrad merged commit 557ff54 into main Apr 6, 2026
11 checks passed
@juanmrad juanmrad deleted the vulnerability-patch-upgrades branch April 6, 2026 04:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants