Skip to content

chore: resolve open dependabot security alerts - #43

Merged
askpt merged 1 commit into
mainfrom
chore/dependabot-alerts
Sep 9, 2026
Merged

askpt merged 1 commit into
mainfrom
chore/dependabot-alerts

Conversation

@jonathannorris

Copy link
Copy Markdown
Member

Summary

  • Resolved 5 open Dependabot security alerts by bumping vulnerable dependencies via overrides (lockfile bump)

Dependabot Alerts Resolved

Alert Package Severity Fix
#134 browserslist high Bumped to 4.28.9 via override >=4.28.7 <5
#132 fast-uri high Bumped to 3.1.7 via override >=3.1.6 <4
#131 fast-uri high Bumped to 3.1.7 via override >=3.1.6 <4
#130 fast-uri high Bumped to 3.1.7 via override >=3.1.6 <4
#129 fast-uri high Bumped to 3.1.7 via override >=3.1.6 <4

- browserslist -> 4.28.9 (high, alert #134)
- fast-uri -> 3.1.7 (high, alerts #129, #130, #131, #132)

Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
@coderabbitai

coderabbitai Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 5d96dec3-a616-48ff-85f4-4607fb7e2410


Comment @coderabbitai help to get the list of available commands.

@jonathannorris
jonathannorris marked this pull request as draft September 8, 2026 13:59
@jonathannorris
jonathannorris marked this pull request as ready for review September 8, 2026 18:40
@askpt
askpt added this pull request to the merge queue Sep 9, 2026
Merged via the queue into main with commit 2ce9025 Sep 9, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants