Skip to content

Fix Dependabot security alerts - #340

Merged
BrianPugh merged 1 commit into
mainfrom
dependabot-security-fixes
Jul 9, 2026
Merged

Fix Dependabot security alerts#340
BrianPugh merged 1 commit into
mainfrom
dependabot-security-fixes

Conversation

@BrianPugh

@BrianPugh BrianPugh commented Jul 9, 2026

Copy link
Copy Markdown
Owner

none of these were reachable, but why not.

Update the wasm and website npm lockfiles to patched dependency versions,
resolving the fixable Dependabot alerts.

wasm: bump js-yaml and ws via `npm audit fix`; force esbuild to ^0.28.1 via an
`overrides` entry (transitive through tsup, which pins ^0.27.0). tsup build
verified.

website: `npm audit fix` bumps shell-quote (critical), fast-uri, ws, qs,
postcss, follow-redirects, http-proxy-middleware, launch-editor, js-yaml, and
webpack-dev-server to patched versions. Production webpack build verified.

All affected packages are dev/build tooling only and are not part of the
shipped tamp wheels or npm package.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@BrianPugh
BrianPugh merged commit 2f59109 into main Jul 9, 2026
3 checks passed
@BrianPugh
BrianPugh deleted the dependabot-security-fixes branch July 9, 2026 18:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant