Skip to content

Bump dependencies to resolve dependabot alerts - #63

Open
Mr-Wallet wants to merge 1 commit into
masterfrom
2-2-8-dependabot
Open

Bump dependencies to resolve dependabot alerts#63
Mr-Wallet wants to merge 1 commit into
masterfrom
2-2-8-dependabot

Conversation

@Mr-Wallet

Copy link
Copy Markdown
Contributor

Summary

  • Run npm audit fix to resolve all 7 dependabot alerts (tar, brace-expansion, ip-address, js-yaml, linkify-it, markdown-it, @babel/core)
  • Bump package version to 2.2.8

All vulnerabilities were in transitive dev/build dependencies. npm audit fix applied semver-compatible updates only (no breaking changes).

Test plan

  • npm audit reports 0 vulnerabilities
  • npm test passes
  • npm run compile succeeds

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@Mr-Wallet
Mr-Wallet requested a review from AlexaXs August 24, 2026 18:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant