Skip to content

fix: patch vulnerabilities and bump outdated dependencies - #7583

Open
waldekmastykarz wants to merge 2 commits into
pnp:mainfrom
waldekmastykarz:waldekmastykarz-dependency-security-refresh
Open

waldekmastykarz wants to merge 2 commits into
pnp:mainfrom
waldekmastykarz:waldekmastykarz-dependency-security-refresh

Conversation

@waldekmastykarz

Copy link
Copy Markdown
Member

Summary

  • updates cooldown-eligible direct dependencies and transitive overrides
  • upgrades csv-parse to 7.0.2 to resolve its prototype replacement vulnerability
  • updates transitive packages through npm audit fix
  • carries forward every dependency, Zod compatibility, and coverage-test change from fix: patch vulnerabilities and bump outdated dependencies #7577 at the same or newer version

Security status

npm audit findings decreased from 35 to 1. The remaining moderate adm-zip symlink-extraction advisory has no fully patched published version: 0.6.0 fixes the older memory-allocation vulnerability, while downgrading to 0.5.8 reintroduces that high-severity issue. The CLI uses adm-zip only to create archives, not to extract untrusted archives.

Not auto-applied

Major-version updates remain for @azure/msal-node, @types/node, eslint-plugin-mocha, mocha, typescript, and several overrides. The latest yaml release is a prerelease.

Validation

  • npm run build
  • npm test
  • 16,092 tests passing
  • 100% statement, branch, function, and line coverage

Supersedes #7577.

waldekmastykarz and others added 2 commits September 14, 2026 09:18
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant