Skip to content

fix(deps): resolve Dependabot security alerts - #71

Merged
kristoffersaastad merged 1 commit into
mainfrom
fix/dependabot-alerts-aug
Aug 20, 2026
Merged

kristoffersaastad merged 1 commit into
mainfrom
fix/dependabot-alerts-aug

Conversation

@kristoffersaastad

Copy link
Copy Markdown
Contributor

Fixes open Dependabot security alerts (lockfile-only changes):

JS (js/package-lock.json)

  • js-yaml 3.15.0 → 3.15.1 and 4.3.0 → 4.3.1 — high: quadratic CPU consumption in !!omap resolution (CVE-2026-59870) — alerts #103, #104
  • brace-expansion 1.1.15 → 1.1.18, 2.1.1 → 2.1.4, 5.0.6 → 5.0.9 — high: exponential-time expansion DoS — alerts #86, #87

Python (python/uv.lock)

  • datamodel-code-generator 0.53.0 → 0.74.0 — fixes code injection, SSRF, and arbitrary file read advisories — alerts #88–#98

Validation

  • npm audit: 0 vulnerabilities; JS test suite passes (68 tests)
  • uv sync succeeds; Python test suite passes (568 passed, 1 skipped)

Update vulnerable transitive dependencies flagged by Dependabot:

JS (js/package-lock.json):
- js-yaml 3.15.0 -> 3.15.1, 4.3.0 -> 4.3.1 (high: quadratic CPU in !!omap, CVE-2026-59870)
- brace-expansion 1.x/2.x/5.x -> patched (high: exponential-time expansion DoS)

Python (python/uv.lock):
- datamodel-code-generator 0.53.0 -> 0.74.0 (high: code injection, SSRF,
  arbitrary file read via $ref, and related advisories; all fixed <= 0.64.0)

Lockfile-only changes. JS tests (68) and Python tests (568) pass.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@kristoffersaastad
kristoffersaastad merged commit 38e20fe into main Aug 20, 2026
10 checks passed
@kristoffersaastad
kristoffersaastad deleted the fix/dependabot-alerts-aug branch August 20, 2026 08:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant