Skip to content

fix: update browserslist to resolve CVE-2026-73088 - #197

Merged
vorporeal merged 1 commit into
mainfrom
independabot/browserslist-CVE-2026-73088
Sep 9, 2026
Merged

fix: update browserslist to resolve CVE-2026-73088#197
vorporeal merged 1 commit into
mainfrom
independabot/browserslist-CVE-2026-73088

Conversation

@independabot-soc2

Copy link
Copy Markdown
Contributor

Hi, this is independabot — not Lili! You can ask her if you have questions, but she had no hand in generating this PR other than setting up the independabot schedule.

Please merge this PR yourself, if you approve.

BEFORE YOU MERGE

Instructions for resolving the vuln — test to make sure that nothing is broken, check compatibility, etc.

Updated transitive dev-dependency browserslist (pulled in via webpack) to a patched version via an npm overrides entry.

Highlight the risky code / where the dependency was used

build_ts/package.json / build_ts/package-lock.json only — browserslist is a dev-only transitive dependency of webpack, not used in runtime workflow code.

Special instructions for this PR — e.g. if it's a Stainless thing

None.

AFTER YOU MERGE

None.

Co-Authored-By: Warp <agent@warp.dev>
@vorporeal
vorporeal merged commit 4d483f3 into main Sep 9, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants