Skip to content

ci: add pnpm audit#1451

Open
AliKdhim87 wants to merge 2 commits into
development-strapi-v5from
add-pnpm-audit
Open

ci: add pnpm audit#1451
AliKdhim87 wants to merge 2 commits into
development-strapi-v5from
add-pnpm-audit

Conversation

@AliKdhim87
Copy link
Copy Markdown
Collaborator

No description provided.

@vercel
Copy link
Copy Markdown

vercel Bot commented May 19, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
cms-frameless-io Ready Ready Preview, Comment May 19, 2026 1:38pm
strapi-overige-objecten-api Ready Ready Preview, Comment May 19, 2026 1:38pm
strapi-pdc-frontend Ready Ready Preview, Comment May 19, 2026 1:38pm

Request Review

…ndencies

- Upgrade next to >=13.5.9 to fix middleware authorization bypass (GHSA-f82v-jwr5-mffw)
- Upgrade vitest to >=2.1.9 to fix potential remote code execution issue (GHSA-9crc-q9x8-hgqq)
- Upgrade handlebars to >=4.7.9 via dependency chain to fix AST injection vulnerability (GHSA-2w6w-674q-4c4q)
- Override sanitize-html to patched version (2.17.4) to mitigate XSS vulnerability (GHSA-rpr9-rxv7-x643)
- Reduce critical vulnerabilities reported by audit
- Improve overall dependency security posture across monorepo
@codecov
Copy link
Copy Markdown

codecov Bot commented May 19, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant