Skip to content

fix: patch vulnerabilities and bump outdated dependencies - #7556

Closed
waldekmastykarz wants to merge 3 commits into
pnp:mainfrom
waldekmastykarz:waldekmastykarz-weekly-deps-bump-00a
Closed

waldekmastykarz wants to merge 3 commits into
pnp:mainfrom
waldekmastykarz:waldekmastykarz-weekly-deps-bump-00a

Conversation

@waldekmastykarz

Copy link
Copy Markdown
Member

Vulnerability Patch Summary

Vulnerabilities fixed: 37 → 0

Packages patched

Direct:

  • axios: ^1.16.1 → ^1.19.0 (fixes 11 high severity vulnerabilities)
  • adm-zip: ^0.5.17 → ^0.6.0 (⚠️ major version bump, fixes high severity memory allocation vuln)
  • applicationinsights: ^3.14.0 → ^3.16.0

Outdated packages updated (semver-compatible):

  • @azure/msal-common: 16.6.2 → 16.13.0
  • @azure/msal-node: 5.2.2 → 5.6.0
  • @inquirer/confirm: 6.1.0 → 6.2.0
  • @inquirer/input: 5.1.0 → 5.1.3
  • @inquirer/select: 5.2.0 → 5.2.2
  • @types/node: 24.12.4 → 24.13.3
  • @types/semver: 7.7.1 → 7.8.0
  • @typescript-eslint/eslint-plugin: 8.60.0 → 8.67.0
  • @typescript-eslint/parser: 8.60.1 → 8.67.0
  • @xmldom/xmldom: 0.9.10 → 0.9.12
  • clipboardy: 5.3.1 → 5.3.2
  • csv-stringify: 6.7.0 → 6.8.3
  • eslint: 10.4.0 → 10.9.0
  • globals: 17.6.0 → 17.11.0
  • mocha: 11.7.6 → 11.8.0
  • open: 11.0.0 → 11.0.1
  • semver: 7.8.1 → 7.8.5
  • sinon: 22.0.0 → 22.1.0
  • tsc-watch: 7.2.0 → 7.2.1
  • uuid: 14.0.0 → 14.0.2

Transitive (via overrides):

  • @opentelemetry/core: → 2.10.0 (fixes moderate baggage propagation vuln)
  • @opentelemetry/propagator-jaeger: → >=2.10.0 (fixes high DoS vuln)
  • protobufjs: 7.6.0 → 7.6.5 (fixes 3 high severity vulnerabilities)
  • @opentelemetry/sdk-node / @opentelemetry/exporter-prometheus: → 0.220.0

Remaining vulnerabilities: 0 🎉

Notes

…kages

Updates:
- axios: ^1.16.1 -> ^1.19.0 (fixes 11 high severity vulnerabilities)
- adm-zip: ^0.5.17 -> ^0.6.0 (fixes high severity memory allocation vuln)
- applicationinsights: ^3.14.0 -> ^3.16.0 (updates transitive OpenTelemetry deps)
- @opentelemetry/core override: 2.10.0 (fixes moderate baggage propagation vuln)
- @opentelemetry/propagator-jaeger override: >=2.10.0 (fixes high DoS vuln)
- protobufjs override: 7.6.5 (fixes 3 high severity vulnerabilities)
- Updates all semver-compatible outdated packages

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@milanholemans

Copy link
Copy Markdown
Contributor

@waldekmastykarz, you made changes to the contributors that have accents in their names. Could you remove this change from the PR, please?

@milanholemans
milanholemans marked this pull request as draft September 1, 2026 19:35
@waldekmastykarz

Copy link
Copy Markdown
Member Author

Totally, that's 100% unintended. Will fix, good catch

@waldekmastykarz

Copy link
Copy Markdown
Member Author

Fixed! Restored all accented characters in contributor names. The unicode escaping was unintended — caused by without . All names now use their proper characters again.

@waldekmastykarz
waldekmastykarz marked this pull request as ready for review September 2, 2026 09:27
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@waldekmastykarz
waldekmastykarz force-pushed the waldekmastykarz-weekly-deps-bump-00a branch from 11ea0ab to d41026f Compare September 2, 2026 09:28
@milanholemans

Copy link
Copy Markdown
Contributor

@waldekmastykarz seems like there are now tests added which are not really part of the PR.

@waldekmastykarz

Copy link
Copy Markdown
Member Author

Superseded by #7577 which includes all changes from this PR plus additional updates.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants