Skip to content

Update npm packages#144

Open
djoreilly wants to merge 1 commit into
SUSE:sensor-base-0.7.0from
djoreilly:npm-security-updates
Open

Update npm packages#144
djoreilly wants to merge 1 commit into
SUSE:sensor-base-0.7.0from
djoreilly:npm-security-updates

Conversation

@djoreilly
Copy link
Copy Markdown

Using npm audit fix

Update axios 1.10.0 -> 1.15.2
Fixes CVE-2025-27152 (bsc#1239305)

Update fast-xml-parser 4.5.1 -> 4.5.6
Fixes CVE-2026-25128 (bsc#1257518)
Fixes CVE-2026-26278 (bsc#1258550)
Fixes CVE-2026-33036 (bsc#1259978)

Update brace-expansion 1.1.12 -> 1.1.14
Fixes CVE-2025-5889 (bsc#1244349)

Update pbkdf2 3.1.2 -> 3.1.5
Fixes CVE-2025-6547 (bsc#1245281)
Fixes CVE-2025-6545 (bsc#1245282)

Update form-data 4.0.0 -> 4.0.5
Fixes CVE-2025-7783 (bsc#1246811)

Update js-yaml 4.1.0 -> 4.1.1
Fixes CVE-2025-64718 (bsc#1255429)

Update lodash 4.17.21 -> 4.18.1
Fixes CVE-2025-13465 (bsc#1257322)

Update minimatch 3.1.2 -> 3.1.5
Fixes CVE-2026-26996 (bsc#1258626)
Fixes CVE-2026-27904 (bsc#1259007)

Update bn.js 4.12.*->4.12.3, 5.2.1->5.2.3,
Fixes CVE-2026-2739 (bsc#1258648)

Update rollup 3.29.5 -> 3.30.0
Fixes CVE-2026-27606 (bsc#1258877)

Using `npm audit fix`

Update axios 1.10.0 -> 1.15.2
Fixes CVE-2025-27152 (bsc#1239305)

Update fast-xml-parser 4.5.1 -> 4.5.6
Fixes CVE-2026-25128 (bsc#1257518)
Fixes CVE-2026-26278 (bsc#1258550)
Fixes CVE-2026-33036 (bsc#1259978)

Update brace-expansion 1.1.12 -> 1.1.14
Fixes CVE-2025-5889 (bsc#1244349)

Update pbkdf2 3.1.2 -> 3.1.5
Fixes CVE-2025-6547 (bsc#1245281)
Fixes CVE-2025-6545 (bsc#1245282)

Update form-data 4.0.0 -> 4.0.5
Fixes CVE-2025-7783 (bsc#1246811)

Update js-yaml 4.1.0 -> 4.1.1
Fixes CVE-2025-64718 (bsc#1255429)

Update lodash 4.17.21 -> 4.18.1
Fixes CVE-2025-13465 (bsc#1257322)

Update minimatch 3.1.2 -> 3.1.5
Fixes CVE-2026-26996 (bsc#1258626)
Fixes CVE-2026-27904 (bsc#1259007)

Update bn.js 4.12.*->4.12.3, 5.2.1->5.2.3,
Fixes CVE-2026-2739 (bsc#1258648)

Update rollup 3.29.5 -> 3.30.0
Fixes CVE-2026-27606 (bsc#1258877)
@djoreilly djoreilly requested a review from xTeixeira April 22, 2026 11:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant