Skip to content

NXT-20661: Update dependencies to fix security vulnerabilities - #167

Open
dan-ichim-lgp wants to merge 3 commits into
developfrom
feature/NXT-20661
Open

dan-ichim-lgp wants to merge 3 commits into
developfrom
feature/NXT-20661

Conversation

@dan-ichim-lgp

@dan-ichim-lgp dan-ichim-lgp commented Oct 1, 2026 •

Copy link
Copy Markdown

Checklist

  • I have read and understand the contribution guide
  • A CHANGELOG entry is included
  • I have run automated testing and it is passed
  • Documentation was added or is not needed
  • This is an API breaking change

Issue Resolved / Feature Added

NXT-20661: Update dependencies to fix security vulnerabilities reported by enact-check-vulnerabilities.

Resolution

Updated package.json and regenerated npm-shrinkwrap.json.

Dependencies:

  • browserslist ^4.29.3 (was ^4.28.2)
  • core-js ^3.50.0 (was 3.22.8)
  • resolve ^1.22.13 (was ^1.22.12)
  • webpack-bundle-analyzer ^5.4.0 (was ^5.3.0)
  • webpack-sources ^3.6.0 (was ^3.5.0)

Dev dependencies:

  • eslint ^9.39.5 (was ^9.39.4)
  • globals ^17.13.0 (was ^17.6.0)
  • html-webpack-plugin ^5.6.8 (was ^5.6.7)
  • prettier ^3.9.9 (was ^3.8.4)
  • react ^19.3.0 (was ^19.2.7)
  • webpack ^5.111.1 (was ^5.107.2)

Overrides added, next to the existing serialize-javascript ^7.0.4:

  • baseline-browser-mapping ^2.11.26
  • brace-expansion@1 1.1.21
  • brace-expansion@5 5.0.12
  • fast-uri ^3.1.8
  • js-yaml@4 4.3.2
    brace-expansion and js-yaml@4 are exact versions, without ^. No brace-expansion@2, brace-expansion@4, or js-yaml@3 override is in the diff.
    No public API change.

Additional Considerations

Links

NXT-20661

Comments

Enact-DCO-1.0-Signed-off-by: Dan Ichim (dan.ichim@lgepartner.com)

@dan-ichim-lgp dan-ichim-lgp self-assigned this Oct 1, 2026
Drop overrides and dependency bumps that do not fix a vulnerability reported on develop, and pin the rest to the lowest same-major release that clears the advisory.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant