Skip to content

Update vulnerable npm dependency paths - #139

Closed
Raymond Zhao (rzhao271) with Copilot wants to merge 1 commit into
mainfrom
copilot/update-npm-dependencies
Closed

Raymond Zhao (rzhao271) with Copilot wants to merge 1 commit into
mainfrom
copilot/update-npm-dependencies

Conversation

Copilot AI commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Component Governance flagged vulnerable npm dependency paths for axios and brace-expansion.

  • Dependency updates

    • axios is resolved at 1.18.0
    • brace-expansion no longer resolves through the vulnerable 1.1.14 path and is resolved through the current minimatch dependency path
  • Lockfile integrity

    • Dependency metadata remains aligned between package.json and package-lock.json
    • No overrides, resolutions, or force install flags are used

Copilot AI linked an issue Sep 14, 2026 that may be closed by this pull request
Copilot AI changed the title [WIP] Update vulnerable npm dependencies Update vulnerable npm dependency paths Sep 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update vulnerable npm dependencies

2 participants