Repository navigation
build(deps-dev): refresh development dependencies and clear security alerts - #98
Merged
Merged
Conversation
…alerts All open security alerts were in development dependencies. This brings `npm audit` to 0 vulnerabilities and covers the updates from the open Dependabot PRs (webpack, browserslist, js-yaml, fast-uri, brace-expansion): - npm audit fix and npm update brace-expansion picomatch refresh the lockfile within the existing ranges, webpack included (5.98.0 to 5.111.1) - mocha 10 to 12 and @typescript-eslint/parser and eslint-plugin 7 to 8, the only way to update serialize-javascript, braces and micromatch - typescript-eslint 8 removed its formatting rules, so .eslintrc.json uses ESLint's own semi rule in place of @typescript-eslint/semi
This was referenced Oct 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
All 26 open Dependabot security alerts are in development dependencies (the extension's only runtime dependency is
vscode-uri). This bringsnpm auditto 0 vulnerabilities in one change, and covers everything in the open Dependabot PRs: #80 (webpack), #88 (browserslist), #89 (js-yaml), #90 (fast-uri) and #92 (brace-expansion).Changes
npm audit fix, plusnpm update brace-expansion picomatchfor the two it left, refresh the lockfile within the existing version ranges. This includes webpack 5.98.0 to 5.111.1, which builds the shipped bundle.mocha10 to 12 and@typescript-eslint/parserandeslint-plugin7 to 8. These are the only way to updateserialize-javascript,bracesandmicromatch, which they pull in..eslintrc.jsonuses ESLint's ownsemirule instead of@typescript-eslint/semi(it was switched off only to defer to that one). Lint reports 0 warnings and 0 errors.Testing
npm audit: 0 vulnerabilities.npm run compile,npm run lint,npm run vscode:prepublishandnpm test(29 passing, on mocha 12).Once this is merged, the Dependabot PRs above can be closed as superseded.