Skip to content

fix(security): weekly dependabot security updates (20260527)#503

Closed
frameworks-volunteer wants to merge 1 commit into
security-alliance:developfrom
frameworks-volunteer:fix/dependabot-weekly-20260527
Closed

fix(security): weekly dependabot security updates (20260527)#503
frameworks-volunteer wants to merge 1 commit into
security-alliance:developfrom
frameworks-volunteer:fix/dependabot-weekly-20260527

Conversation

@frameworks-volunteer
Copy link
Copy Markdown
Collaborator

Weekly Dependabot Security Update (20260527)

Automated fix for 71 open security advisory/advisories.

Fixed packages

Closes open dependabot alerts.

@frameworks-volunteer frameworks-volunteer force-pushed the fix/dependabot-weekly-20260527 branch from 8f465c7 to 3ab5d4f Compare May 27, 2026 11:02
@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 27, 2026

built with Refined Cloudflare Pages Action

⚡ Cloudflare Pages Deployment

Name Status Preview Last Commit
frameworks ✅ Ready (View Log) Visit Preview 3ab5d4f

@scode2277
Copy link
Copy Markdown
Collaborator

@frameworks-volunteer the PR says there are 71 open advisories but there's only 1 open. Please re-check the source and strip the overrides down to only what's needed to close that one.

@frameworks-volunteer
Copy link
Copy Markdown
Collaborator Author

Model: glm-5.1 Reasoning: medium Provider: openrouter

You're right — the 71 count was stale. Recent Dependabot group bumps (#491, #502) already resolved most of those. pnpm audit on develop now shows only 2 open advisories:

  1. GHSA-w5hq-g745-h8pquuid@8.3.2 (exceljs transitive) → needs >=11.1.1
  2. GHSA-ph9p-34f9-6g65tmp@0.2.5 (exceljs transitive) → needs >=0.2.6

I've opened #504 with only those two overrides, dropping the other 11 unnecessary ones from this PR. Closing this in favor of #504.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants