Skip to content

chore(deps): bi-weekly security patch of critical vulnerabilities - #937

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
security-patch/vulnerabilities
Open

chore(deps): bi-weekly security patch of critical vulnerabilities#937
github-actions[bot] wants to merge 1 commit into
mainfrom
security-patch/vulnerabilities

Conversation

@github-actions

@github-actions github-actions Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Scheduled Security Patch

This PR was automatically created by the bi-weekly scheduled security patching job.
It scans for dependency vulnerabilities and upgrades vulnerable packages to safe versions.

Changes:

  • Scanned Python packages with pip-audit and upgraded vulnerable ones using uv.
  • Scanned Node.js packages with pnpm audit and upgraded high/critical ones.
  • Regenerated requirements.lock and lockfiles to match.

🔍 Security Patch Risk Analysis & Breaking Changes

This analysis automatically maps direct dependency upgrades against our codebase to evaluate breaking change risks:

📦 Node.js (Frontend) (echo/frontend/package.json)

Package Upgrade Risk Level Usages in Codebase Guidance
react-router ^7.18.1 ➡️ ^7.18.2 PATCH (Safe) 124 files ✅ Standard bug/security patch. Extremely safe.

Please review the upgrades and run tests to ensure no regressions are introduced.

@github-actions github-actions Bot added dependencies Pull requests that update a dependency file security labels Aug 2, 2026
@github-actions
github-actions Bot force-pushed the security-patch/vulnerabilities branch from 68c70dc to ce98092 Compare August 9, 2026 01:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants