Skip to content
This repository was archived by the owner on Jun 8, 2026. It is now read-only.

Security: Update transitive dependency resolutions - #47

Merged
Xeonus merged 1 commit into
mainfrom
automated/security-resolutions
Apr 22, 2026
Merged

Security: Update transitive dependency resolutions#47
Xeonus merged 1 commit into
mainfrom
automated/security-resolutions

Conversation

@github-actions

@github-actions github-actions Bot commented Apr 13, 2026

Copy link
Copy Markdown

Summary

Automated update of resolutions in package.json to fix vulnerable transitive dependencies.
Sources: Dependabot alerts (medium/high/critical) + yarn audit.

Changes

Dependency Before After Severity Source
@hono/node-server (none) ^1.19.13 moderate yarn-audit
axios ^1.13.5 ^1.15.0 moderate yarn-audit
basic-ftp ^5.2.0 ^5.3.0 high yarn-audit
follow-redirects (none) ^1.16.0 moderate yarn-audit
hono (none) ^4.12.14 moderate yarn-audit
protobufjs ^7.2.5 ^7.5.5 critical yarn-audit

Note: This only updates transitive dependencies via resolutions. Direct dependency upgrades should be done manually to avoid breaking changes.

Verify

  • yarn install succeeds
  • yarn build succeeds
  • App runs correctly

@github-actions github-actions Bot added dependencies Pull requests that update a dependency file security labels Apr 13, 2026
@github-actions
github-actions Bot force-pushed the automated/security-resolutions branch from fea223b to a2ce860 Compare April 20, 2026 09:56
@github-actions

Copy link
Copy Markdown
Author

Visit the preview URL for this PR (updated for commit a2ce860):

https://aura-analytics-1c4b3--pr47-automated-security-r-6t9b5zx3.web.app

(expires Wed, 29 Apr 2026 06:46:27 GMT)

🔥 via Firebase Hosting GitHub Action 🌎

Sign: c0deaa906c7e63346edc0f82cfa5e568e017f8d2

@Xeonus
Xeonus merged commit eab303f into main Apr 22, 2026
2 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant