Skip to content

fix(deps): update vulnerable development dependencies - #194

Merged
TheRealAgentK merged 1 commit into
mainfrom
security/remediate-dev-dependency-advisories
Sep 2, 2026
Merged

TheRealAgentK merged 1 commit into
mainfrom
security/remediate-dev-dependency-advisories

Conversation

@TheRealAgentK

Copy link
Copy Markdown
Contributor

Summary

  • update fast-uri from 3.1.5 to the patched 3.1.6 release
  • update qs from 6.15.3 to the patched 6.16.0 release
  • retain the existing known-clean Keyv/Cacheable supply-chain safety overrides

fast-uri@3.1.6 is deliberately used instead of 3.1.7 because 3.1.7 was published on the day of this update. The updated package tarballs and lifecycle metadata were reviewed, registry signatures were verified, and the final dependency tree had no matches in the current multi-vendor Shai-Hulud/ChainDrop IOC feed.

Verification

  • npm run prepare
  • npm test
  • npm run eslint
  • npm run tseslint
  • npm run prettier:check
  • npm audit
  • npm audit --omit=dev
  • npm audit signatures

All checks pass and npm reports zero vulnerabilities.

@QuantumNightmare QuantumNightmare left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@TheRealAgentK
TheRealAgentK merged commit ae1de86 into main Sep 2, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants