Skip to content

Bump picomatch, js-yaml, and node-forge to patched versions#157

Open
Copilot wants to merge 2 commits intomainfrom
copilot/add-daily-activity-report-workflow
Open

Bump picomatch, js-yaml, and node-forge to patched versions#157
Copilot wants to merge 2 commits intomainfrom
copilot/add-daily-activity-report-workflow

Conversation

Copy link
Copy Markdown

Copilot AI commented Apr 8, 2026

Three transitive dev dependencies had known vulnerabilities. This applies the exact version bumps from Dependabot PRs #153, #154, and #155 in a single update to package-lock.json.

Dependency updates

Package Old New Notes
picomatch 2.3.0 2.3.2 Fixes CVE-2026-33671 & CVE-2026-33672
js-yaml 4.1.0 4.1.1
node-forge 1.3.1 1.4.0

Only package-lock.json is modified — six entries updated (both the node_modules and legacy flat sections for each package). No package.json changes; these are unpinned transitive deps resolved at install time.

Copilot AI linked an issue Apr 8, 2026 that may be closed by this pull request
Copilot AI changed the title [WIP] Add daily activity report workflow Bump picomatch, js-yaml, and node-forge to patched versions Apr 8, 2026
Copilot AI requested a review from Dedac April 8, 2026 15:25
Copilot finished work on behalf of Dedac April 8, 2026 15:25
@Dedac Dedac marked this pull request as ready for review April 10, 2026 22:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

📊 Daily Activity Report — 2026-04-08

2 participants