Skip to content

npm audit fix for high/low severity alerts#437

Open
samirromdhani wants to merge 1 commit into
mainfrom
fix/npm-audit-fix
Open

npm audit fix for high/low severity alerts#437
samirromdhani wants to merge 1 commit into
mainfrom
fix/npm-audit-fix

Conversation

@samirromdhani

@samirromdhani samirromdhani commented Jul 22, 2026

Copy link
Copy Markdown

Please check if the PR fulfills these requirements

  • The commit message follows our guidelines
  • Tests for the changes have been added (for bug fixes / features)
  • Docs have been added / updated (for bug fixes / features)
  • A PR or issue has been opened in all impacted repositories (if any)

Does this PR already have an issue describing the problem?

What kind of change does this PR introduce?

Fix

What is the current behavior?

npm audit

8 vulnerabilities (2 low, 6 high)

What is the new behavior (if this is a feature change)?

npm audit

found 0 vulnerabilities

Does this PR introduce a breaking change or deprecate an API?

  • Yes
  • No

If yes, please check if the following requirements are fulfilled

  • The Breaking Change or Deprecated label has been added
  • The migration steps are described in the following section

What changes might users need to make in their application due to this PR? (migration steps)

Other information:

npm audit --fix
Package From To GitHub Advisory
fast-uri 3.1.2 3.1.4 CVE-2026-16221
js-yaml 4.2.0 4.3.0 CVE-2026-59869
svgo 3.3.3 3.3.4 GHSA-2p49-hgcm-8545
vite 7.3.2 7.3.6 CVE-2026-53571
ws 8.19.0 8.21.1 CVE-2026-48779
brace-expansion 1.1.14 / 2.1.0 / 5.0.5 1.1.16 / 2.1.2 / 5.0.7 CVE-2026-13149
@babel/core 7.29.0 7.29.7 CVE-2026-49356
esbuild 0.27.3 0.28.1 GHSA-g7r4-m6w7-qqqr

Signed-off-by: Samir Romdhani <samir.romdhani_externe@rte-france.com>
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant