Skip to content

Patch remaining keeperapi toolchain CVEs (npm audit -> 0)#155

Merged
tylerccarson merged 2 commits into
mainfrom
patch-toolchain-cves
May 29, 2026
Merged

Patch remaining keeperapi toolchain CVEs (npm audit -> 0)#155
tylerccarson merged 2 commits into
mainfrom
patch-toolchain-cves

Conversation

@tylerccarson
Copy link
Copy Markdown
Contributor

Resolve the 11 remaining dev/toolchain advisories via npm audit fix (patched backports exist within existing semver ranges -- no major bumps). Bump rollup-plugin-typescript2 ^0.32.1 -> ^0.37.0, which fixes its include pattern for the new picomatch so .ts files are still transformed (rollup stays 2.x).

Also add "moduleResolution": "node" to tsconfig.rollup.json: rpt2 0.37 type-checks more strictly and surfaced a ../qrc resolution failure under module: es6, which this resolves.

Resolve the 11 remaining dev/toolchain advisories via npm audit fix
(patched backports exist within existing semver ranges -- no major bumps).
Bump rollup-plugin-typescript2 ^0.32.1 -> ^0.37.0, which fixes its include
pattern for the new picomatch so .ts files are still transformed (rollup stays 2.x).

Also add "moduleResolution": "node" to tsconfig.rollup.json: rpt2 0.37
type-checks more strictly and surfaced a ../qrc resolution failure under
module: es6, which this resolves.
@socket-security
Copy link
Copy Markdown

socket-security Bot commented May 29, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedrollup-plugin-typescript2@​0.32.1 ⏵ 0.37.090 +210010081 -2100
Updatedrollup@​2.79.2 ⏵ 2.80.089 +1100 +1610098100

View full report

@tylerccarson tylerccarson merged commit 3395ebe into main May 29, 2026
6 checks passed
@tylerccarson tylerccarson deleted the patch-toolchain-cves branch May 29, 2026 22:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants