Skip to content

deps: update vulnerable transitive dependencies - #9872

Merged
martinrrm merged 3 commits into
release/v11from
deps/vulnerable-transitives-v11
Aug 25, 2026
Merged

deps: update vulnerable transitive dependencies#9872
martinrrm merged 3 commits into
release/v11from
deps/vulnerable-transitives-v11

Conversation

@martinrrm

Copy link
Copy Markdown
Contributor

Summary

  • updates bundled brace-expansion from 5.0.7 to 5.0.9
  • updates bundled ip-address from 10.2.0 to 10.5.0
  • updates bundled undici from 6.27.0 to 6.28.0
  • refreshes nested development copies of brace-expansion to 1.1.18

The production audit now reports only the separate tar advisory addressed by #9842.

Testing

  • node . run dependencies --ignore-scripts
  • node . ls brace-expansion ip-address undici --all --omit=dev
  • node . audit --omit=dev --json
  • TMPDIR=$PWD/.tmp node . test --ignore-scripts

@martinrrm
martinrrm requested review from a team as code owners August 13, 2026 21:22
@martinrrm
martinrrm force-pushed the deps/vulnerable-transitives-v11 branch from 49bbbfb to a9da8b2 Compare August 18, 2026 21:41
martinrrm and others added 3 commits August 18, 2026 15:01
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3f0ccf56-34fa-491a-9f58-ad4c6de7cd02
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3f0ccf56-34fa-491a-9f58-ad4c6de7cd02
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3f0ccf56-34fa-491a-9f58-ad4c6de7cd02
@martinrrm
martinrrm force-pushed the deps/vulnerable-transitives-v11 branch from a9da8b2 to 8e3bc8a Compare August 18, 2026 22:06
@martinrrm

Copy link
Copy Markdown
Contributor Author

I think we can ignore this one and just backport #9871, initially I was getting different changes, but they are now equal

@martinrrm
martinrrm merged commit 4791b27 into release/v11 Aug 25, 2026
20 checks passed
@martinrrm
martinrrm deleted the deps/vulnerable-transitives-v11 branch August 25, 2026 20:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants