Skip to content

Update dependencies - #48

Merged
jstayton merged 2 commits into
developmentfrom
update-dependencies-2026-10
Oct 5, 2026
Merged

jstayton merged 2 commits into
developmentfrom
update-dependencies-2026-10

Conversation

@jstayton

@jstayton jstayton commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Patch and minor updates only; there are no majors and no overrides. The lockfile moves to v3 in its own commit; no resolved versions change.

npm audit still reports high-severity advisories in undici, basic-ftp, and the proxy-agent chain, all pulled in by release-it, which pins them exactly. The only fix npm offers is downgrading to release-it v20. They're dev-only and never ship to consumers.

🤖 Generated with Claude Code

jstayton and others added 2 commits October 3, 2026 10:55
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
npm 11's `npm update` converts v2 lockfiles to v3 regardless, and
v2's extra v1 data only serves npm 6, which nothing here uses. No
resolved versions change; the v1 `dependencies` section is dropped.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@jstayton
jstayton merged commit 95c7c8c into development Oct 5, 2026
5 checks passed
@jstayton
jstayton deleted the update-dependencies-2026-10 branch October 5, 2026 09:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant