Skip to content

deps: update vulnerable transitive dependencies - #9871

Open
martinrrm wants to merge 1 commit into
latestfrom
deps/vulnerable-transitives-latest
Open

deps: update vulnerable transitive dependencies#9871
martinrrm wants to merge 1 commit into
latestfrom
deps/vulnerable-transitives-latest

Conversation

@martinrrm

Copy link
Copy Markdown
Contributor

Summary

  • updates bundled brace-expansion from 5.0.7 to 5.0.9
  • updates bundled ip-address from 10.2.0 to 10.5.0
  • updates bundled undici from 6.27.0 to 6.28.0
  • refreshes nested development copies of brace-expansion to 1.1.18

The production audit now reports only the separate tar advisory addressed by #9843.

Testing

  • node . run dependencies --ignore-scripts
  • node . ls brace-expansion ip-address undici --all --omit=dev
  • node . audit --omit=dev --json
  • TMPDIR=$PWD/.tmp node . test --ignore-scripts

Updates brace-expansion to 5.0.9, ip-address to 10.5.0, and undici to 6.28.0.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 05f1eae6-8532-40e8-ba49-31cf9a6b8424
@martinrrm
martinrrm requested review from a team as code owners August 13, 2026 21:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant