Skip to content

Fix CVEs: postcss, js-yaml, svgo, fast-uri, brace-expansion, react-router-dom - #135

Merged
mraible merged 1 commit into
mainfrom
fix/cve-july-2026
Aug 11, 2026
Merged

Fix CVEs: postcss, js-yaml, svgo, fast-uri, brace-expansion, react-router-dom#135
mraible merged 1 commit into
mainfrom
fix/cve-july-2026

Conversation

@mraible

@mraible mraible commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

Updates dependencies to resolve security vulnerabilities:

  • react-router-dom 7.17.0 → 7.18.2 (multiple CVEs)
  • postcss 8.5.14 → 8.5.18 (direct devDependency update)
  • js-yaml → 4.3.0 (prototype pollution)
  • svgo → 3.3.4
  • fast-uri → 3.1.5 (ReDoS)
  • brace-expansion@1 → 1.1.16, brace-expansion@5 → 5.0.7 (ReDoS)

…brace-expansion 1.1.16/5.0.7, react-router-dom 7.18.2
@mraible
mraible requested a review from a team August 10, 2026 16:00
@mraible
mraible enabled auto-merge (squash) August 10, 2026 17:15
@mraible
mraible merged commit 508c9c5 into main Aug 11, 2026
19 checks passed
@mraible
mraible deleted the fix/cve-july-2026 branch August 11, 2026 16:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants