Skip to content

Bump vulnerable dev dependencies#259

Merged
huntie merged 1 commit into
mainfrom
nc/dependency-bumps
Jun 4, 2026
Merged

Bump vulnerable dev dependencies#259
huntie merged 1 commit into
mainfrom
nc/dependency-bumps

Conversation

@cortinico
Copy link
Copy Markdown

Summary

  • bump vulnerable root dev dependencies and refresh lockfile entries
  • refresh vulnerable scripts/migration/class-fields transitive dependencies
  • bump vendored puppeteer-replay Rollup packages to the fixed range

Test plan

  • PATH=/tmp/depot_tools:third_party/depot_tools:$PATH NODE_OPTIONS=--max-old-space-size=8192 npm run lint
  • PATH=/tmp/depot_tools:third_party/depot_tools:$PATH npm run prebuild
  • PATH=/tmp/depot_tools:third_party/depot_tools:$PATH npm run build

@meta-cla meta-cla Bot added the cla signed label Jun 4, 2026
@cortinico cortinico requested a review from huntie June 4, 2026 13:27
@cortinico cortinico marked this pull request as ready for review June 4, 2026 13:27
Comment thread package.json
},
"overrides": {
"@types/estree": "1.0.6",
"nanoid": "3.3.8",
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note to self: All above deps are aligned (or greater) in upstream ChromeDevTools org repo. However, this serialize-javascript override will remain consequential ✅

Image

@huntie huntie merged commit 950f4a8 into main Jun 4, 2026
5 checks passed
@huntie huntie deleted the nc/dependency-bumps branch June 4, 2026 13:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants