Skip to content

Bump transitive dependency flatted from 3.4.1 to 3.4.2#3424

Merged
ashfame merged 1 commit intotrunkfrom
dependabot_security_alert_fix
Mar 20, 2026
Merged

Bump transitive dependency flatted from 3.4.1 to 3.4.2#3424
ashfame merged 1 commit intotrunkfrom
dependabot_security_alert_fix

Conversation

@ashfame
Copy link
Copy Markdown
Member

@ashfame ashfame commented Mar 20, 2026

Summary

  • Upgrades the transitive dependency flatted from 3.4.1 to 3.4.2 to resolve Dependabot security alert #265
  • flatted is pulled in transitively via eslintflat-cache and @nx/reactlog4js, both of which use semver ranges (^3.2.x) that already allow 3.4.2
  • Only the lockfile resolution changed — no direct dependency upgrades needed

Test plan

  • Verify npm ls flatted shows 3.4.2
  • Verify CI passes (no functional changes, only lockfile update)

Made with Cursor

Resolves Dependabot security alert #265.

Made-with: Cursor
@ashfame ashfame requested review from a team, JanJakes and Copilot March 20, 2026 13:48
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@ashfame ashfame self-assigned this Mar 20, 2026
@ashfame ashfame merged commit 016f4a4 into trunk Mar 20, 2026
92 of 93 checks passed
@ashfame ashfame deleted the dependabot_security_alert_fix branch March 20, 2026 15:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants