Skip to content

Conversation

@spawnia
Copy link
Member

@spawnia spawnia commented Dec 3, 2025

Summary

  • Updates glob from 10.3.10 → 10.5.0 and 11.0.3 → 11.1.0 (fixes high severity command injection vulnerability)
  • Updates js-yaml from 3.14.1 → 3.14.2 and 4.1.0 → 4.1.1 (fixes medium severity prototype pollution vulnerability)

These are transitive dependencies updated via yarn up -R glob js-yaml.

Fixes https://github.com/mll-lab/react-components/security/dependabot

Test plan

  • Lint passes
  • Typecheck passes
  • Tests pass (89/89)

🤖 Generated with Claude Code

- glob 10.3.10 → 10.5.0 (CVE command injection)
- glob 11.0.3 → 11.1.0 (CVE command injection)
- js-yaml 3.14.1 → 3.14.2 (prototype pollution)
- js-yaml 4.1.0 → 4.1.1 (prototype pollution)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
@spawnia spawnia requested a review from KathrinPindl2 December 3, 2025 08:16
@spawnia spawnia requested a review from mic-web December 16, 2025 08:53
@mic-web mic-web merged commit 17ef476 into master Dec 16, 2025
6 checks passed
@mic-web mic-web deleted the fix-vulnerabilities branch December 16, 2025 09:09
github-actions bot pushed a commit that referenced this pull request Dec 16, 2025
## [20.2.2](v20.2.1...v20.2.2) (2025-12-16)

### Bug Fixes

* **deps:** update glob and js-yaml to fix security vulnerabilities ([#319](#319)) ([17ef476](17ef476))
@github-actions
Copy link

🎉 This PR is included in version 20.2.2 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Development

Successfully merging this pull request may close these issues.

3 participants