Skip to content

build(deps): fix braces vulnerability (GHSA-vfj7-8cjw-p6xm) - #68

Merged
tembleking merged 2 commits into
mainfrom
fix/npm-audit-braces
Oct 8, 2026
Merged

tembleking merged 2 commits into
mainfrom
fix/npm-audit-braces

Conversation

@tembleking

Copy link
Copy Markdown
Member

Fixes all npm audit findings (11 high, braces GHSA-vfj7-8cjw-p6xm) and supersedes #67, #63, #57, #56.

  • @vscode/vsce ^3.9.2 → ^4.0.0 (requires Node ≥22; devShell uses Node 24)
  • @typescript-eslint/* ^7 → ^8 (still compatible with eslint 8 / .eslintrc)
  • overrides.ovsx.@vscode/vsce → root version (ovsx only uses createVSIX, still exported in v4; we publish a prebuilt .vsix anyway)
  • @typescript-eslint/semi (removed in v8) → core semi

Verified: npm audit 0 vulns, lint, check-types, vsce package, nix build, 64 tests passing.

- Bump @vscode/vsce to ^4.0.0 (drops secretlint/globby/fast-glob chain)
- Bump @typescript-eslint/* to ^8 (drops globby from typescript-estree)
- Override ovsx's @vscode/vsce to the root version (no ovsx release supports vsce 4 yet)
- Replace removed @typescript-eslint/semi rule with core semi
- Includes markdown-it 14.3.2, fast-uri 3.1.8, linkify-it 5.0.2, brace-expansion 1.1.21
@tembleking
tembleking requested a review from a team as a code owner October 8, 2026 10:01
@tembleking
tembleking merged commit 58575d7 into main Oct 8, 2026
7 checks passed
@tembleking
tembleking deleted the fix/npm-audit-braces branch October 8, 2026 10:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants