Skip to content

chore(deps): bump vulnerable website deps to resolve security alerts#999

Merged
B4nan merged 1 commit into
masterfrom
chore/security-deps-bump
Jun 17, 2026
Merged

chore(deps): bump vulnerable website deps to resolve security alerts#999
B4nan merged 1 commit into
masterfrom
chore/security-deps-bump

Conversation

@B4nan

@B4nan B4nan commented Jun 17, 2026

Copy link
Copy Markdown
Member

Resolves Dependabot security alerts in the docs website (pnpm project). Lockfile-only bump via pnpm update joi js-yaml -r — no overrides or hand-edited versions.

Fixed

  • joi: 17.13.3 → 17.13.4 (consumers repointed; duplicate 17.13.3 resolution removed)
  • js-yaml: ≥ 4.2.0 already resolved in the lockfile (no change needed for the v4 line)

Not addressed here

  • js-yaml 3.14.2 remains via gray-matter@4.0.3, which pins js-yaml@^3.x and cannot be moved to v4 without a gray-matter upgrade. Out of scope for a lockfile-only bump.

🤖 Generated with Claude Code

@B4nan B4nan added the adhoc Ad-hoc unplanned task added during the sprint. label Jun 17, 2026
@github-actions github-actions Bot added this to the 143rd sprint - Tooling team milestone Jun 17, 2026
@github-actions github-actions Bot added the t-tooling Issues with this label are in the ownership of the tooling team. label Jun 17, 2026
@codecov

codecov Bot commented Jun 17, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 90.51%. Comparing base (726620b) to head (8aed5b7).
⚠️ Report is 4 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master     #999      +/-   ##
==========================================
- Coverage   90.54%   90.51%   -0.04%     
==========================================
  Files          49       49              
  Lines        3132     3132              
==========================================
- Hits         2836     2835       -1     
- Misses        296      297       +1     
Flag Coverage Δ
e2e 36.14% <ø> (ø)
integration 57.12% <ø> (-0.04%) ⬇️
unit 79.27% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@B4nan B4nan requested a review from barjin June 17, 2026 13:56
@B4nan B4nan merged commit 4ccb991 into master Jun 17, 2026
52 of 54 checks passed
@B4nan B4nan deleted the chore/security-deps-bump branch June 17, 2026 14:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

adhoc Ad-hoc unplanned task added during the sprint. t-tooling Issues with this label are in the ownership of the tooling team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants