Skip to content

Comments

fix: resolve npm audit vulnerabilities in eslint dependencies#237

Merged
timowestnosto merged 2 commits intodependabot/npm_and_yarn/patch-updates-ded1a45e23from
copilot/sub-pr-235
Feb 23, 2026
Merged

fix: resolve npm audit vulnerabilities in eslint dependencies#237
timowestnosto merged 2 commits intodependabot/npm_and_yarn/patch-updates-ded1a45e23from
copilot/sub-pr-235

Conversation

Copy link
Contributor

Copilot AI commented Feb 23, 2026

Context

Upgraded eslint and typescript-eslint to resolve security vulnerabilities flagged by npm audit. The vulnerabilities were ReDoS issues in ajv and minimatch dependencies.

Related Jira ticket

Screenshots


Changes:

  • eslint: ^9.37.0^10.0.1
  • typescript-eslint: ^8.46.0^8.56.1-alpha.3

Result: 0 vulnerabilities (down from 11)

The canary typescript-eslint version was necessary as it's the first to include minimatch 10.2.2+, which patches GHSA-3ppc-4f35-3m26.


✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

…ities

Co-authored-by: timowestnosto <13622115+timowestnosto@users.noreply.github.com>
Copy link
Contributor Author

Copilot AI commented Feb 23, 2026

Just as a heads up, I was blocked by some firewall rules while working on your feedback. Expand below for details.

Warning

Firewall rules blocked me from connecting to one or more addresses (expand for details)

I tried to connect to the following addresses, but was blocked by firewall rules:

  • api.nosto.com
    • Triggering command: /opt/hostedtoolcache/node/24.13.0/x64/bin/node /opt/hostedtoolcache/node/24.13.0/x64/bin/node --conditions node --conditions development --experimental-import-meta-resolve --require /home/REDACTED/work/nosto-cli/nosto-cli/node_modules/vitest/suppress-warnings.cjs /home/REDACTED/work/nosto-cli/nosto-cli/node_modules/vitest/dist/workers/forks.js (dns block)

If you need me to access, download, or install something from one of these locations, you can either:

Copilot AI changed the title [WIP] Bump the patch-updates group with 4 updates fix: resolve npm audit vulnerabilities in eslint dependencies Feb 23, 2026
Copilot AI requested a review from timowestnosto February 23, 2026 06:04
@timowestnosto timowestnosto marked this pull request as ready for review February 23, 2026 06:29
@timowestnosto timowestnosto merged commit e7c46fc into dependabot/npm_and_yarn/patch-updates-ded1a45e23 Feb 23, 2026
3 checks passed
@timowestnosto timowestnosto deleted the copilot/sub-pr-235 branch February 23, 2026 06:33
@nosto-release-public
Copy link

🎉 This PR is included in version 1.2.5 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants