Skip to content

fix(deps): remediate Dependabot vulnerabilities - #357

Merged
drewstone merged 2 commits into
mainfrom
chore/dependabot-soc2-20260901
Sep 2, 2026
Merged

drewstone merged 2 commits into
mainfrom
chore/dependabot-soc2-20260901

Conversation

@drewstone

Copy link
Copy Markdown
Contributor

Summary

  • upgrade vulnerable JavaScript dependency paths to patched releases
  • remove stale ip resolution and enforce supported Node 22 CI runtime
  • refresh the Yarn lockfile

Verification

  • yarn --ignore-engines compile
  • yarn --ignore-engines build:packages
  • yarn --ignore-engines ts-check (two pre-existing TypeScript errors remain)
  • yarn --ignore-engines fast (environment-only fixture and Ganache failures remain)

All changes are dependency remediation only; no Dependabot alerts were dismissed.

@drewstone
drewstone merged commit 3c1d88e into main Sep 2, 2026
4 checks passed
@drewstone
drewstone deleted the chore/dependabot-soc2-20260901 branch September 2, 2026 03:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant