Skip to content

Bump remaining vulnerable dev dependencies#260

Open
cortinico wants to merge 1 commit into
mainfrom
nc/dependency-bumps-remaining
Open

Bump remaining vulnerable dev dependencies#260
cortinico wants to merge 1 commit into
mainfrom
nc/dependency-bumps-remaining

Conversation

@cortinico
Copy link
Copy Markdown

@cortinico cortinico commented Jun 4, 2026

Summary:

  • Bump Rollup to a fixed 4.59.x-compatible version
  • Update the lockfile for qs, flatted, follow-redirects, and basic-ftp fixed versions
  • Add a scoped Mocha override so its minimatch 4.x dependency resolves to 4.2.5

Verification:

  • npm run lint
  • npm run prebuild
  • npm run build

@meta-cla meta-cla Bot added the cla signed label Jun 4, 2026
@cortinico cortinico requested a review from huntie June 4, 2026 15:20
@cortinico cortinico marked this pull request as ready for review June 4, 2026 15:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant