Skip to content

Resolve Dependabot vulnerabilities in root and examples - #543

Merged
rosston merged 1 commit into
mainfrom
fix-dependabot-vulnerabilities
Sep 21, 2026
Merged

rosston merged 1 commit into
mainfrom
fix-dependabot-vulnerabilities

Conversation

@rosston

@rosston rosston commented Sep 21, 2026

Copy link
Copy Markdown
Member
  • Run npm audit fix on the root lockfile (using Node 16 / npm 8 to keep the lockfile compatible with the oldest supported version)
  • Remove deprecated codeclimate-test-reporter and the cover:report and cover:ci scripts that used it; it pulled in request, form-data, qs, tough-cookie and uuid, and cover:ci only ran on Node 8
  • Re-resolve example lockfiles with npm update
  • Migrate examples/babel from Babel 6 (no patched versions) to Babel 7

Remaining root alerts: elliptic (no patched release, via browserify) and uuid via nyc (fix requires nyc 18, which needs Node 20+).

- Run npm audit fix on the root lockfile (using Node 16 / npm 8 to keep
  the lockfile compatible with the oldest supported version)
- Remove deprecated codeclimate-test-reporter and the cover:report and
  cover:ci scripts that used it; it pulled in request, form-data, qs,
  tough-cookie and uuid, and cover:ci only ran on Node 8
- Re-resolve example lockfiles with npm update
- Migrate examples/babel from Babel 6 (no patched versions) to Babel 7

Remaining root alerts: elliptic (no patched release, via browserify) and
uuid via nyc (fix requires nyc 18, which needs Node 20+).
@rosston rosston self-assigned this Sep 21, 2026
@rosston
rosston marked this pull request as ready for review September 21, 2026 19:35
@rosston
rosston merged commit 0e28af9 into main Sep 21, 2026
12 checks passed
@rosston
rosston deleted the fix-dependabot-vulnerabilities branch September 21, 2026 19:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant