Skip to content

AVRO-4252: Update JS dependencies with security issues#3753

Merged
RyanSkraba merged 1 commit intoapache:mainfrom
iemejia:AVRO-4252-js-deps-main
May 5, 2026
Merged

AVRO-4252: Update JS dependencies with security issues#3753
RyanSkraba merged 1 commit intoapache:mainfrom
iemejia:AVRO-4252-js-deps-main

Conversation

@iemejia
Copy link
Copy Markdown
Member

@iemejia iemejia commented May 2, 2026

Summary

  • Remove deprecated coveralls dependency (source of unfixable vulnerabilities via request)
  • Add npm overrides to force safe versions of transitive dependencies: diff 8.0.4, serialize-javascript 7.0.5, lodash 4.18.1, minimatch 3.1.5, uuid 14.0.0
  • Resolves all 18 npm audit vulnerabilities to 0

Testing

All 383 tests pass on Node.js 20, 22, and 24.

R: @RyanSkraba

@github-actions github-actions Bot added the JS label May 2, 2026
@iemejia iemejia requested a review from RyanSkraba May 2, 2026 17:00
@iemejia iemejia force-pushed the AVRO-4252-js-deps-main branch 2 times, most recently from 094f191 to 5360d8c Compare May 2, 2026 19:49
@iemejia iemejia force-pushed the AVRO-4252-js-deps-main branch from 5360d8c to 3e58de0 Compare May 4, 2026 22:57
@RyanSkraba RyanSkraba merged commit 8dffb87 into apache:main May 5, 2026
16 checks passed
@iemejia iemejia deleted the AVRO-4252-js-deps-main branch May 6, 2026 13:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants