Skip to content

chore: resolve open dependabot security alerts - #587

Merged
jonathannorris merged 2 commits into
mainfrom
chore/dependabot-alerts
Sep 16, 2026
Merged

jonathannorris merged 2 commits into
mainfrom
chore/dependabot-alerts

Conversation

@jonathannorris

Copy link
Copy Markdown
Member

Summary

  • Resolved 8 open Dependabot security alerts by bumping vulnerable dependencies

Dependabot Alerts Resolved

Alert Package Severity Fix
#318 js-yaml (3.x line) high Bumped resolution to 3.15.2
#317 js-yaml (4.x line) high Bumped resolution and direct dep to 4.3.2
#316 sharp high Added resolution pinning to 0.35.4 (transitive via miniflare)
#315 vitest medium Bumped devDependency to 4.1.11 (root and mcp-worker)
#314 @vitest/mocker medium Resolved automatically via vitest 4.1.11 bump
#313 hono medium Bumped resolution and mcp-worker direct dep to 4.13.5
#312 hono medium Same fix as above
#311 hono medium Same fix as above

Generated with Claude Code

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 15, 2026 11:47
@jonathannorris
jonathannorris requested a review from a team as a code owner September 15, 2026 11:47
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
devcycle-mcp-server 35d369c Sep 15 2026, 11:47 AM

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Update the license-check exclusion for the new Sharp package version.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Updates vulnerable dependencies to resolve eight Dependabot security alerts across the CLI and MCP worker.

Changes:

  • Bumps js-yaml, hono, and vitest.
  • Pins sharp to a patched release.
  • Regenerates the Yarn lockfile.
File summaries
File Summary
package.json Updates dependencies and security resolutions; the license-check exclusion must also be updated.
mcp-worker/package.json Updates worker dependencies.
yarn.lock Records patched dependency versions and checksums.
Review details
  • Files reviewed: 2/3 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread package.json
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

No unresolved review issues remain, and the dependency updates address the listed security alerts.

Review details
  • Files reviewed: 3/4 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

@jonathannorris
jonathannorris merged commit aa9f06c into main Sep 16, 2026
7 checks passed
@jonathannorris
jonathannorris deleted the chore/dependabot-alerts branch September 16, 2026 13:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants