Skip to content

chore(other): resolve shell-quote and js-cookie CVE#315

Merged
illiaRedoc merged 3 commits into
mainfrom
chore/bump-shell-quote
Jun 12, 2026
Merged

chore(other): resolve shell-quote and js-cookie CVE#315
illiaRedoc merged 3 commits into
mainfrom
chore/bump-shell-quote

Conversation

@illiaRedoc

@illiaRedoc illiaRedoc commented Jun 11, 2026

Copy link
Copy Markdown
Contributor

What/Why/How?

Reference

Testing

Screenshots (optional)

Check yourself

  • Code is linted
  • Tested
  • All new/updated code is covered with tests

Security

  • Security impact of change has been considered
  • Code follows company security practices and guidelines

@illiaRedoc illiaRedoc requested a review from a team as a code owner June 11, 2026 15:41

@redocly redocly Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

marketing-site AI Review: 🟢 Completed

Reunite Agent has reviewed your changes and found 4 potential issue(s).

Note

Low Risk

This PR strictly updates package overrides to resolve security vulnerabilities (CVEs) in third-party dependencies, carrying minimal risk to application behavior.

Overview

Bumps shell-quote to version 1.8.4 and js-cookie to version 3.0.7 via package.json overrides to address known CVEs (CVE-2026-9277 and CVE-2026-46625). Correspondingly updates package-lock.json to reflect the newly resolved dependency versions.

@illiaRedoc illiaRedoc changed the title chore(other): override shell-quote to use 1.8.4 chore(other): resolve shell-quote and js-cookie CVE Jun 11, 2026
Comment thread package.json
Comment thread package.json Outdated
Comment thread package.json Outdated
Comment thread package.json
@illiaRedoc illiaRedoc merged commit a55074a into main Jun 12, 2026
7 checks passed
@illiaRedoc illiaRedoc deleted the chore/bump-shell-quote branch June 12, 2026 07:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants