Skip to content

deps: update vulnerable transitive dependencies - #9872

Open
martinrrm wants to merge 1 commit into
release/v11from
deps/vulnerable-transitives-v11
Open

deps: update vulnerable transitive dependencies#9872
martinrrm wants to merge 1 commit into
release/v11from
deps/vulnerable-transitives-v11

Conversation

@martinrrm

Copy link
Copy Markdown
Contributor

Summary

  • updates bundled brace-expansion from 5.0.7 to 5.0.9
  • updates bundled ip-address from 10.2.0 to 10.5.0
  • updates bundled undici from 6.27.0 to 6.28.0
  • refreshes nested development copies of brace-expansion to 1.1.18

The production audit now reports only the separate tar advisory addressed by #9842.

Testing

  • node . run dependencies --ignore-scripts
  • node . ls brace-expansion ip-address undici --all --omit=dev
  • node . audit --omit=dev --json
  • TMPDIR=$PWD/.tmp node . test --ignore-scripts

Updates brace-expansion to 5.0.9, ip-address to 10.5.0, and undici to 6.28.0.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 05f1eae6-8532-40e8-ba49-31cf9a6b8424
@martinrrm
martinrrm requested review from a team as code owners August 13, 2026 21:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant