Skip to content

chore(deps): npm audit fix - #49

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
audit-fix
Open

chore(deps): npm audit fix#49
github-actions[bot] wants to merge 1 commit into
mainfrom
audit-fix

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown

Automated dependency fixes produced by npm audit fix --omit=dev.

Security Summary (npm audit --omit=dev)

  • Before fix: critical=0, high=0, moderate=1, low=0, info=0 (npm exit code 1; expected when vulnerabilities are present)
  • After fix: critical=0, high=0, moderate=0, low=0, info=0

Top findings before fix (prod dependencies only):

  • [moderate] morgan: morgan vulnerable to Log Forging via unescaped Unicode line separators (GHSA-jxfw-x594-9x9m)

Full audit JSON reports are attached as workflow artifacts (audit-before.json, audit-after.json).
Please review lockfile changes and run CI/tests before merging.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant