Skip to content

fix(security): bump deps to resolve new vulnerabilities#2715

Draft
billhimmelsbach wants to merge 8 commits intomasterfrom
5495-security-updates
Draft

fix(security): bump deps to resolve new vulnerabilities#2715
billhimmelsbach wants to merge 8 commits intomasterfrom
5495-security-updates

Conversation

@billhimmelsbach
Copy link
Copy Markdown
Contributor

@billhimmelsbach billhimmelsbach commented Mar 23, 2026

Updates a few resolutions and merges some dependabot PRs.

Changes

  • jspdf from 4.2.0 to 4.2.1
  • rollup from 4.48.1 to 4.59.0
  • flatted from 3.3.3 to 3.4.2
  • immutable from 4.3.7 to 4.3.8
  • tar from 7.5.9 to 7.5.11
  • serialize-javascript from 5.0.1 to 7.0.3
  • minimatch from 10.2.1 to 10.2.3

Testing

  1. Does it look good on staging?
  2. Do the tests still pass?

Closes GHE #5495

billhimmelsbach and others added 8 commits March 23, 2026 04:48
Bumps [rollup](https://github.com/rollup/rollup) from 4.48.1 to 4.59.0.
- [Release notes](https://github.com/rollup/rollup/releases)
- [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG.md)
- [Commits](rollup/rollup@v4.48.1...v4.59.0)

---
updated-dependencies:
- dependency-name: rollup
  dependency-version: 4.59.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [flatted](https://github.com/WebReflection/flatted) from 3.3.3 to 3.4.2.
- [Commits](WebReflection/flatted@v3.3.3...v3.4.2)

---
updated-dependencies:
- dependency-name: flatted
  dependency-version: 3.4.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [immutable](https://github.com/immutable-js/immutable-js) from 4.3.7 to 4.3.8.
- [Release notes](https://github.com/immutable-js/immutable-js/releases)
- [Changelog](https://github.com/immutable-js/immutable-js/blob/main/CHANGELOG.md)
- [Commits](immutable-js/immutable-js@v4.3.7...v4.3.8)

---
updated-dependencies:
- dependency-name: immutable
  dependency-version: 4.3.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [tar](https://github.com/isaacs/node-tar) from 7.5.9 to 7.5.11.
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](isaacs/node-tar@v7.5.9...v7.5.11)

---
updated-dependencies:
- dependency-name: tar
  dependency-version: 7.5.11
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [serialize-javascript](https://github.com/yahoo/serialize-javascript) from 5.0.1 to 7.0.3.
- [Release notes](https://github.com/yahoo/serialize-javascript/releases)
- [Commits](yahoo/serialize-javascript@v5.0.1...v7.0.3)

---
updated-dependencies:
- dependency-name: serialize-javascript
  dependency-version: 7.0.3
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant