Skip to content

version updates for npm deps flagged up as vulnerable by scanner#141

Open
vredchenko wants to merge 2 commits intomainfrom
update-npm-deps
Open

version updates for npm deps flagged up as vulnerable by scanner#141
vredchenko wants to merge 2 commits intomainfrom
update-npm-deps

Conversation

@vredchenko
Copy link
Copy Markdown
Contributor

No description provided.

@vredchenko vredchenko changed the title version updates for npm deps fallged up as vulnerable by scanner version updates for npm deps flagged up as vulnerable by scanner Feb 11, 2026
@vredchenko vredchenko marked this pull request as ready for review February 11, 2026 13:25
@akademy akademy self-requested a review March 2, 2026 14:38
Copy link
Copy Markdown
Member

@akademy akademy left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks good. However, my IDE has flagged up a couple more vulnerabilities (via Mend.io)

It recommends rollup goes to 4.59.0 and storybook to 8.6.17. Can you bump those too?

https://osv.dev/vulnerability/GHSA-mjf5-7g4m-gx5w
https://osv.dev/vulnerability/GHSA-mw96-cpmx-2vgc

@akademy
Copy link
Copy Markdown
Member

akademy commented Apr 23, 2026

Any update on this?

@vredchenko
Copy link
Copy Markdown
Contributor Author

Any update on this?

Requested changes not in scope of this PR. Requested changes are blocking merge of PR.

The GHSA-r5fr-rjxr-66jc advisory now flags <=4.17.23 as vulnerable,
requiring >=4.18.0. lodash 4.18.1 is published on npm and is out of
the vulnerable range. This unblocks pnpm audit --audit-level high
in CI.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants