Skip to content

chore(deps): bump tmp to 0.2.7#644

Merged
B4nan merged 1 commit into
masterfrom
chore/sec-tmp-bump
May 29, 2026
Merged

chore(deps): bump tmp to 0.2.7#644
B4nan merged 1 commit into
masterfrom
chore/sec-tmp-bump

Conversation

@B4nan
Copy link
Copy Markdown
Member

@B4nan B4nan commented May 28, 2026

Summary

  • Bumps the transitive tmp dependency (via nx/lerna devDependencies) from 0.2.5 to 0.2.7, resolving the high-severity Dependabot alert GHSA-52f5-9888-hmc6 (arbitrary temp file/directory write via symlink).
  • Lockfile-only change; the existing semver range already permits 0.2.7, so no manifest or override changes were needed.

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@github-actions github-actions Bot added this to the 141st sprint - Tooling team milestone May 28, 2026
@github-actions github-actions Bot added the t-tooling Issues with this label are in the ownership of the tooling team. label May 28, 2026
@B4nan B4nan added the adhoc Ad-hoc unplanned task added during the sprint. label May 28, 2026
@B4nan B4nan requested a review from barjin May 29, 2026 10:36
@B4nan B4nan merged commit 7e0b16f into master May 29, 2026
9 of 10 checks passed
@B4nan B4nan deleted the chore/sec-tmp-bump branch May 29, 2026 10:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

adhoc Ad-hoc unplanned task added during the sprint. t-tooling Issues with this label are in the ownership of the tooling team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants