Skip to content

fix: non-breakin gdependabot security updates#281

Merged
SchnozzleCat merged 1 commit intomainfrom
fix/dependabot-security-updates
Apr 14, 2026
Merged

fix: non-breakin gdependabot security updates#281
SchnozzleCat merged 1 commit intomainfrom
fix/dependabot-security-updates

Conversation

@SchnozzleCat
Copy link
Copy Markdown
Contributor

@SchnozzleCat SchnozzleCat commented Apr 14, 2026

Summary

Vulnerabilities Fixed

Patched critical/high/medium vulnerabilities in handlebars (JS
injection, prototype pollution), lodash/lodash-es (code injection, prototype pollution), undici (HTTP
smuggling, CRLF injection, WebSocket issues), flatted (prototype pollution), serialize-javascript
(DoS), yaml (stack overflow), picomatch (method injection), and webpack (SSRF bypass).

Dependencies

Updated all semver-compatible packages including @babel/core, @chakra-ui/react,
@storybook/, @typescript-eslint/, framer-motion, esbuild, eslint, react-datepicker, semantic-release,
and others to their latest non-breaking versions.
Pinned react-dom to avoid pulling react 19 version

@vercel
Copy link
Copy Markdown

vercel Bot commented Apr 14, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
boemly Ready Ready Preview, Comment Apr 14, 2026 1:32pm

Request Review

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 14, 2026

size-limit report 📦

Path Size Loading time (3g) Running time (snapdragon) Total time
dist/index.js 166.62 KB (-26.34% 🔽) 3.4 s (-26.34% 🔽) 170 ms (-16.74% 🔽) 3.6 s
dist/index.cjs 284.24 KB (-12.49% 🔽) 5.7 s (-12.49% 🔽) 2.4 s (-50.4% 🔽) 8.1 s

@SchnozzleCat SchnozzleCat merged commit 7447ea2 into main Apr 14, 2026
8 checks passed
@SchnozzleCat SchnozzleCat deleted the fix/dependabot-security-updates branch April 14, 2026 13:41
@github-actions
Copy link
Copy Markdown

🎉 This PR is included in version 10.3.1 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants