Skip to content

fix: bump vulnerable transitive dependencies#8809

Open
pranavjain97 wants to merge 1 commit into
masterfrom
wcn-567
Open

fix: bump vulnerable transitive dependencies#8809
pranavjain97 wants to merge 1 commit into
masterfrom
wcn-567

Conversation

@pranavjain97
Copy link
Copy Markdown
Contributor

@pranavjain97 pranavjain97 commented May 19, 2026

WCN-566

  • protobufjs ^7.5.8 in 5 modules (was 7.2.5/^7.4.0/^7.5.0, fixes GHSA-xq3m-2v4x-88gg critical)
  • sanitize-html ^2.17.4 in sdk-api (was ^2.11, fixes GHSA-rpr9-rxv7-x643 critical)
  • serialize-javascript 7.0.5 in root resolution (was 7.0.3)

@pranavjain97 pranavjain97 requested a review from a team as a code owner May 19, 2026 22:12
@linear-code
Copy link
Copy Markdown

linear-code Bot commented May 19, 2026

WCN-567

WCN-566

- protobufjs ^7.5.8 in 5 modules (fixes GHSA-xq3m-2v4x-88gg critical)
- sanitize-html ^2.17.4 in sdk-api (fixes GHSA-rpr9-rxv7-x643 critical)
- serialize-javascript 7.0.5 in root resolution (was 7.0.3)
- protobufjs 7.5.8 in root resolution (was 7.5.6)
Copy link
Copy Markdown

@bhargavirao24 bhargavirao24 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving the changes for bypass for the CVE fixes. I still ran the dependency cooldown skill for it and everything looks good. This is safe to merge.

Image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants