Skip to content

fix: patch transitive dep CVEs in nextjs-frontend via yarn resolutions#285

Merged
luarss merged 1 commit into
The-OpenROAD-Project:masterfrom
luarss:claude/adoring-noether-9yOgN
Jun 4, 2026
Merged

fix: patch transitive dep CVEs in nextjs-frontend via yarn resolutions#285
luarss merged 1 commit into
The-OpenROAD-Project:masterfrom
luarss:claude/adoring-noether-9yOgN

Conversation

@luarss
Copy link
Copy Markdown
Collaborator

@luarss luarss commented Jun 4, 2026

Summary

All four advisories now clear; yarn audit reports 0 vulnerabilities.

Pin brace-expansion >=1.1.13 (CVE-2026-33750, CVE-2025-5889),
@eslint/plugin-kit >=0.3.4 (GHSA-xffm-g5w8-qvg7), and
ajv >=6.14.0 (CVE-2025-69873) to their patched versions.
All four advisories now clear; yarn audit reports 0 vulnerabilities.

https://claude.ai/code/session_01SBgjmJodHCRpFysr7ss1Dn
Signed-off-by: Jack Luar <jluar@precisioninno.com>
@luarss luarss merged commit ac09c57 into The-OpenROAD-Project:master Jun 4, 2026
2 checks passed
@luarss luarss deleted the claude/adoring-noether-9yOgN branch June 4, 2026 13:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant