Skip to content

Fix CVEs: postcss, js-yaml, svgo, fast-uri, brace-expansion, react-router-dom - #111

Merged
mraible merged 1 commit into
mainfrom
fix/cve-july-2026
Aug 11, 2026
Merged

Fix CVEs: postcss, js-yaml, svgo, fast-uri, brace-expansion, react-router-dom#111
mraible merged 1 commit into
mainfrom
fix/cve-july-2026

Conversation

@mraible

@mraible mraible commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

Updates dependencies to resolve security vulnerabilities:

  • react-router-dom 7.17.0 → 7.18.2 (multiple CVEs)
  • postcss 8.5.14 → 8.5.18 (direct devDependency update)
  • js-yaml → 4.3.0 (prototype pollution)
  • svgo → 3.3.4
  • fast-uri → 3.1.5 (ReDoS)
  • brace-expansion@1 → 1.1.16, brace-expansion@5 → 5.0.7 (ReDoS)

…brace-expansion 1.1.16/5.0.7, react-router-dom 7.18.2
@mraible
mraible requested a review from a team August 10, 2026 16:00
@mraible
mraible enabled auto-merge (squash) August 10, 2026 19:14
@mraible
mraible merged commit 2277667 into main Aug 11, 2026
9 checks passed
@mraible
mraible deleted the fix/cve-july-2026 branch August 11, 2026 16:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants