Skip to content

Update dependencies#10

Merged
jkyberneees merged 3 commits intomasterfrom
chore/update-dependencies
Mar 28, 2026
Merged

Update dependencies#10
jkyberneees merged 3 commits intomasterfrom
chore/update-dependencies

Conversation

@jkyberneees
Copy link
Copy Markdown
Collaborator

No description provided.

- find-my-way: 9.3.0 → 9.5.0
- chai: 4.3.7 → 6.2.2
- mocha: 11.7.2 → 11.7.5
- nyc: 17.1.0 → 18.0.0
- supertest: 7.1.4 → 7.2.2

All tests pass with maintained code coverage (98.96% lines).
No breaking changes detected.
Resolved 3 vulnerabilities:
- serialize-javascript RCE (HIGH, CVSS 8.1) - GHSA-5c6j-r48x-rmvq
- serialize-javascript DoS (MODERATE, CVSS 5.9) - GHSA-qj8w-gfj5-8c6v
- diff DoS (LOW) - GHSA-73rr-hh4g-fpgx

Changes:
- Downgrade mocha from 11.7.5 to 11.3.0
- Add npm overrides for diff@^5.2.0 (safe version)
- Add npm overrides for serialize-javascript@^7.0.5 (safe version)

Verification:
✅ npm audit: 0 vulnerabilities
✅ All 10 tests passing
✅ Code coverage: 98.96% (maintained)
✅ No breaking changes
- Update setup-node action from v1 to v4
- Update Node.js version from 16.x to 22.x (latest stable)
- Ensures CI runs on modern Node.js with latest features and security patches
@jkyberneees jkyberneees merged commit f789dda into master Mar 28, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant