Skip to content

fix: update 4 vulnerable dependencies - #93

Merged
rdietrick merged 1 commit into
mainfrom
vuln-fix/2026-10-02
Oct 7, 2026
Merged

rdietrick merged 1 commit into
mainfrom
vuln-fix/2026-10-02

Conversation

@rdietrick

Copy link
Copy Markdown
Collaborator

Vulnerability Fix

This PR was generated by the Copilot SDK agent (auto).

Changes Applied

  • serialize-javascript: 6.0.2 → 7.0.5 [package.json, package-lock.json]
  • js-yaml: 4.3.0 → 4.3.2 [package.json, package-lock.json]
  • uuid: 8.x/9.x → 11.1.1 [package.json, package-lock.json]
  • markdown-it: 14.2.0 → 14.3.1 [package.json, package-lock.json]

Skipped

  • ip-address: Salesforce CLI embedded copies remain at 10.3.1 and bundled npm copy 10.2.0
  • fast-uri: Salesforce CLI embedded copy remains at 3.1.5
  • undici: Salesforce CLI embedded copy remains at 7.29.0 and bundled npm copy at 6.27.0
  • path-to-regexp: already-at-fix

Vulnerabilities Addressed

Package Fix Version CVE/ID
serialize-javascript 7.0.5 GHSA-5c6j-r48x-rmvq
serialize-javascript 7.0.5 GHSA-qj8w-gfj5-8c6v
js-yaml 4.3.2 GHSA-5p4m-2wfm-xmqj
js-yaml 4.3.2 GHSA-2883-xcg3-v3hh
uuid 11.1.1 GHSA-w5hq-g745-h8pq
ip-address 10.5.1 GHSA-mwp4-54f8-5fhr
ip-address 10.5.1 GHSA-rpw4-54j3-4h4q
ip-address 10.5.1 GHSA-2vr4-cq9g-pvrc
ip-address 10.5.1 GHSA-4xrf-jv44-h6hh
ip-address 10.5.1 GHSA-22jq-vg5j-6vgg
fast-uri 3.1.7 GHSA-f65p-4m7j-42xc
fast-uri 3.1.7 GHSA-jqff-g426-hqxp
fast-uri 3.1.7 GHSA-fph4-wmhf-6fwf
fast-uri 3.1.7 GHSA-5jgf-p345-68v8
fast-uri 3.1.7 GHSA-qw65-cvwx-89v3
markdown-it 14.3.1 GHSA-253c-mchw-3w2r
path-to-regexp 1.9.0 GHSA-9wv6-86v2-598j
undici 7.29.1 GHSA-8xcm-r25x-g524
undici 7.29.1 GHSA-m8rv-5g2x-5cg5
undici 7.29.1 GHSA-v3r7-h72x-cjcm
undici 7.29.1 GHSA-r53p-7pc4-xj5r
undici 7.29.1 GHSA-w293-vg96-wgc3
undici 7.29.1 GHSA-pmjh-fq2x-6v4x
undici 7.29.1 GHSA-2jfj-6hjv-fm6j
undici 7.29.1 GHSA-8436-99hf-9mmv
undici 7.29.1 GHSA-2gqq-gqf2-x968

Related Dependabot PRs

These Dependabot PRs overlap with this one but include updates it does not cover, so they may stay open.

Generated by sec-vuln-fixer using Copilot SDK (auto)

Requested by @rdietrick

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 2, 2026 22:04
@rdietrick rdietrick added sec-vuln-fixer Created by sec-vuln-fixer security Security-related change labels Oct 2, 2026
@rdietrick rdietrick added the severity:high High severity vulnerability label Oct 2, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The lockfile still resolves vulnerable versions of three updated dependencies.

Review effort: Balanced
Findings: 3 High severity

Open (3)
What changed in this PR

Updates dependency overrides to address transitive vulnerabilities in the project’s Salesforce CI/CD tooling.

Changes:

  • Updates js-yaml and markdown-it.
  • Attempts to update nested undici, fast-uri, and ip-address dependencies.
File Description
package.json Updates security-related dependency overrides.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread package.json
Comment thread package.json
Comment thread package.json
@rdietrick
rdietrick merged commit 20bb369 into main Oct 7, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

sec-vuln-fixer Created by sec-vuln-fixer security Security-related change severity:high High severity vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants