Skip to content

Dependency security updates#19

Closed
dmattia wants to merge 3 commits intomainfrom
cursor/dependency-security-updates-8f9f
Closed

Dependency security updates#19
dmattia wants to merge 3 commits intomainfrom
cursor/dependency-security-updates-8f9f

Conversation

@dmattia
Copy link
Copy Markdown
Member

@dmattia dmattia commented Feb 18, 2026

This PR updates tar and lodash to address multiple Dependabot security advisories.

Yarn resolutions were used to force the minimum required versions for these transitive dependencies.

  • tar is now resolved to 7.5.9 (addresses advisories requiring >=7.5.3, >=7.5.4, >=7.5.7, >=7.5.8).
  • lodash is now resolved to 4.17.23 (addresses advisory requiring >=4.17.23).

All tests (yarn test) and build (yarn build) passed after the update.

Related Issues

  • [none]

Security Implications

[none]

System Availability

[none]


Open in Cursor Open in Web

Co-authored-by: David Mattia <dmattia@users.noreply.github.com>
@cursor
Copy link
Copy Markdown

cursor bot commented Feb 18, 2026

Cursor Agent can help with this pull request. Just @cursor in comments and I'll start working on changes in this branch.
Learn more about Cursor Agents

cursoragent and others added 2 commits February 18, 2026 18:51
Co-authored-by: David Mattia <dmattia@users.noreply.github.com>
Co-authored-by: David Mattia <dmattia@users.noreply.github.com>
@dmattia dmattia closed this Feb 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants