Skip to content
This repository was archived by the owner on Oct 16, 2025. It is now read-only.

chore: Update dependencies to resolve audit warnings#425

Merged
Gudahtt merged 1 commit intomainfrom
resolve-audit-issues
Oct 15, 2025
Merged

chore: Update dependencies to resolve audit warnings#425
Gudahtt merged 1 commit intomainfrom
resolve-audit-issues

Conversation

@Gudahtt
Copy link
Copy Markdown
Member

@Gudahtt Gudahtt commented Oct 15, 2025

Update dependencies that Socket warned about in #423


Note

Refreshes yarn.lock with updates to cross-spawn, form-data, get-intrinsic, and related transitive packages, adding helper libs and tightening mime-types range.

  • Dependencies (yarn.lock):
    • Upgrades:
      • cross-spawn 7.0.3 → 7.0.6
      • form-data 3.0.1 → 3.0.4 (now depends on es-set-tostringtag, hasown; updates mime-types to ^2.1.35)
      • get-intrinsic 1.2.2 → 1.3.1 (adds multiple deps)
      • gopd 1.0.1 → 1.2.0
      • has-symbols 1.0.3 → 1.1.0
      • has-tostringtag 1.0.0 → 1.0.2
    • New transitive packages: async-function, async-generator-function, generator-function, call-bind-apply-helpers, dunder-proto, es-define-property, es-errors, es-object-atoms@1.1.1, es-set-tostringtag@2.1.0, get-proto, math-intrinsics.
    • Constraint change: mime-types consolidated to ^2.1.35.

Written by Cursor Bugbot for commit d530228. This will update automatically on new commits. Configure here.

@Gudahtt Gudahtt marked this pull request as ready for review October 15, 2025 17:32
@Gudahtt Gudahtt requested a review from a team as a code owner October 15, 2025 17:32
@socket-security
Copy link
Copy Markdown

socket-security bot commented Oct 15, 2025

@socket-security
Copy link
Copy Markdown

socket-security bot commented Oct 15, 2025

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

Ignoring alerts on:

  • async-function@1.0.0

View full report

@Gudahtt
Copy link
Copy Markdown
Member Author

Gudahtt commented Oct 15, 2025

@SocketSecurity ignore npm/async-function@1.0.0
New author OK

@Gudahtt Gudahtt enabled auto-merge (squash) October 15, 2025 17:38
Update dependencies that Socket warned about in #423
@Gudahtt Gudahtt force-pushed the resolve-audit-issues branch from a6eefaa to d530228 Compare October 15, 2025 17:44
@Gudahtt Gudahtt merged commit bbbc67e into main Oct 15, 2025
20 checks passed
@Gudahtt Gudahtt deleted the resolve-audit-issues branch October 15, 2025 17:47
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants