Skip to content

chore(deps): security bumps — axios, engine.io, brace-expansion#266

Merged
sunny-se merged 2 commits into
mainfrom
security/dependabot-bulk-20260723
Jul 24, 2026
Merged

chore(deps): security bumps — axios, engine.io, brace-expansion#266
sunny-se merged 2 commits into
mainfrom
security/dependabot-bulk-20260723

Conversation

@chikara1608

Copy link
Copy Markdown
Collaborator

Summary

Security-only dependency bumps for the axe-core submodule, applied via npm overrides (durable across lockfile regeneration). Lockfile kept at v2. No source (.js) changes.

Resolves

Jira Package Advisory Patched to
AXE-3878 axios GHSA-gcfj-64vw-6mp9 1.18.0
AXE-3879 engine.io GHSA-r635-g3xr-vw7x 6.6.7
AXE-3886 brace-expansion GHSA-3jxr-9vmj-r5cp @1 1.1.16 / @2 2.1.2 / @5 5.0.7

All three are transitive deps, so they're pinned through overrides (matches the repo's existing ws/websocket-driver pattern). Existing Dependabot PRs were insufficient (e.g. #223 only reached axios 1.16.1, below the 1.18.0 patch floor).

Verification

  • Every resolved node in package-lock.json is at/above the advisory patch floor (both packages and legacy dependencies trees).
  • Lint findings in lib/ are pre-existing and unrelated (no .js touched).

🤖 Generated with Claude Code

chikara1608 and others added 2 commits July 24, 2026 00:45
Add npm overrides so these transitive deps resolve to non-vulnerable
versions (durable across lockfile regeneration). Lockfile kept at v2.

- axios 1.18.0                                  GHSA-gcfj-64vw-6mp9  AXE-3878
- engine.io 6.6.7                               GHSA-r635-g3xr-vw7x  AXE-3879
- brace-expansion @1 1.1.16 / @2 2.1.2 / @5 5.0.7  GHSA-3jxr-9vmj-r5cp  AXE-3886

[a11y-critical]: security-only dependency bumps in the axe-core submodule
(package.json is JSON, so the impact tag is recorded in this message).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
js-yaml 3.15.0/4.3.0 (GHSA-52cp-r559-cp3m, AXE-3891) and
linkify-it 5.0.2 (GHSA-v245-v573-v5vm, AXE-3892) via package.json
overrides. Both are transitive dev/build tooling deps (js-yaml via
grunt; linkify-it via markdown-it -> jsdoc docs). No runtime impact.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@browserstack browserstack deleted a comment from chikara1608 Jul 24, 2026
@sunny-se
sunny-se merged commit 20c8c89 into main Jul 24, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants