Haritha
8549b9f8f5
fix: resolve npm audit high severity vulnerabilities ( #1347 )
...
- Upgrade fast-xml-parser to 5.10.1 (fixes GHSA-8r6m-32jq-jx6q)
- Add package.json override to force brace-expansion >=5.0.8 across
all transitive dependencies (fixes GHSA-mh99-v99m-4gvg) without
downgrading jest/ts-jest
- Refresh .licenses/npm cache to match updated dependency tree
- Rebuild dist/setup and dist/cache-save
npm audit now reports 0 vulnerabilities. Pre-existing test suite
failures (7 suites, ESM/jest teardown issue) verified unrelated to
this change - identical on unmodified main with node 24.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-08-03 11:18:19 -05:00
Priya Gupta
f8cf4291c8
Migrate to ESM and upgrade dependencies ( #1330 )
...
* Migrate to ESM and upgrade dependencies
* Add ESM migration note to README for V7
* Remove unnecessary devDependencies: ts-node, @types/jest
* npm audit fix
* Upgrade @types/node to version 26.0.0
* Clarify ESM migration details in README for V7
* Update README and dependencies
* Fix lint issue
2026-07-15 11:40:44 -05:00
Jason Ginchereau
6731c2ba87
Resolve high-severity audit issues
2026-06-18 18:02:00 -07:00
Copilot
c8813ba1bc
Upgrade @actions dependencies and update licenses ( #1303 )
...
Agent-Logs-Url: https://github.com/actions/setup-python/sessions/d7501c8f-2fae-40ed-a7fc-e78f5087585a
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: gowridurgad <159780674+gowridurgad@users.noreply.github.com>
2026-04-15 12:25:40 -05:00
dependabot[bot]
28f2168f4d
Bump minimatch from 3.1.2 to 3.1.5 ( #1281 )
...
* Bump minimatch from 3.1.2 to 3.1.5
Bumps [minimatch](https://github.com/isaacs/minimatch ) from 3.1.2 to 3.1.5.
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md )
- [Commits](https://github.com/isaacs/minimatch/compare/v3.1.2...v3.1.5 )
---
updated-dependencies:
- dependency-name: minimatch
dependency-version: 3.1.5
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
* Check failure fix
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: gowridurgad <gowridurgad@gmail.com>
2026-03-09 10:05:35 -05:00
Salman Chishti
bfe8cc55a7
Upgrade @actions dependencies to Node 24 compatible versions ( #1259 )
...
* Upgrade @actions dependencies to Node 24 compatible versions
Upgrades the following @actions packages:
- @actions/cache: ^4.0.3 → ^5.0.1
- @actions/core: ^1.10.0 → ^2.0.1
- @actions/exec: ^1.1.0 → ^2.0.0
- @actions/http-client: ^2.2.3 → ^3.0.0
- @actions/io: ^1.0.2 → ^2.0.0
License updates:
- Add blueoak-1.0.0 to allowed licenses (new transitive dependency: sax)
- Add @actions/http-client to reviewed licenses (MIT licensed but detected as 'other')
Also ran npm audit fix to resolve vulnerabilities.
* update patch version
* upgrade actions/checkout from v5 to v6
* check failures fix
* revert the pinned pipenv version
* check failure fix
* npm run build
---------
Co-authored-by: Aparna Jyothi <aparnajyothi-y@github.com>
2026-01-20 09:38:55 -06:00