Skip to content

Upgrade dependencies and fix vulnerabilities - #19

Merged
KennethWussmann merged 1 commit into
mainfrom
task/upgrade-deps-20260919-210006
Sep 19, 2026
Merged

KennethWussmann merged 1 commit into
mainfrom
task/upgrade-deps-20260919-210006

Conversation

@KennethWussmann

Copy link
Copy Markdown
Owner

Why

Routine dependency maintenance. Everything is moved to its latest version, known
security advisories are resolved, and overrides are checked for whether they are still needed.

What

Upgrades

Package From To
@types/node ^26.5.1 ^26.6.2
eslint ^10.10.0 ^10.11.0
mocha ^12.0.1 ^12.0.2

Security

pnpm audit reports no known vulnerabilities.

The toml@<4.2.0 -> >=4.2.0 override was tested for removal but is still load-bearing: without it toml resolves to 2.3.6 via markdown-toc > gray-matter, reintroducing two high-severity prototype-pollution advisories (GHSA-82x6-q7mm-w9cf, GHSA-v5mp-jgw5-2x6j). Kept.

Still open

Item Current Wanted Blocker
typescript 6.0.3 7.0.2 typescript-eslint 8.70.0 does not support TS 7 (typescript-eslint#10940). Build passes on TS 7 but pnpm lint hard-fails. Held at ^6.0.3; retry once typescript-eslint ships TS 7 support.

Verification

The repo has no test files, so verification is build plus lint (matching CI, which runs only build).

  • pnpm build - pass
  • pnpm lint - pass
  • pnpm audit - no known vulnerabilities

Written by Claude Opus 4.8 via Pi

Co-authored-by: Claude Opus 4.8 via [Pi](https://pi.dev/) <noreply@pi.dev>
@KennethWussmann
KennethWussmann marked this pull request as ready for review September 19, 2026 19:02
@KennethWussmann
KennethWussmann merged commit 812d70a into main Sep 19, 2026
1 check passed
@KennethWussmann
KennethWussmann deleted the task/upgrade-deps-20260919-210006 branch September 19, 2026 19:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant