Skip to content

[WTF-2591]: Fix vulnerabilities in transitive dependencies of PWT#174

Open
weirdwater wants to merge 3 commits intomasterfrom
wtf/wtf-2591-fix-vulnerabilities
Open

[WTF-2591]: Fix vulnerabilities in transitive dependencies of PWT#174
weirdwater wants to merge 3 commits intomasterfrom
wtf/wtf-2591-fix-vulnerabilities

Conversation

@weirdwater
Copy link
Copy Markdown
Collaborator

No description provided.

weirdwater and others added 3 commits April 22, 2026 17:27
Removed fast-xml-parser from command-tests package as it was not used
anywhere in the code. This fixes a critical vulnerability
(CVE-2026-25896) related to entity encoding bypass.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Updated Babel core and related packages to resolve potential
vulnerabilities in transitive dependencies:
- @babel/core: 7.26.0 → 7.29.0
- @babel/preset-env: 7.26.0 → 7.29.2
- @babel/preset-react: 7.25.9 → 7.28.5
- @babel/plugin-transform-*: 7.25.9 → 7.28.6

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants