Skip to content

fix: deps#217

Closed
robmonct wants to merge 80 commits intoUnleash:mainfrom
checkout-anywhere:robmonct/fix_critical_vuln
Closed

fix: deps#217
robmonct wants to merge 80 commits intoUnleash:mainfrom
checkout-anywhere:robmonct/fix_critical_vuln

Conversation

@robmonct
Copy link
Copy Markdown

@robmonct robmonct commented Feb 3, 2026

About the changes

Closes #

Important files

Discussion points

robmonct and others added 25 commits December 9, 2024 15:01
* fix: add resolutions for path-to-regexp for router (Unleash#198)

* task: resolve cookie to 1.0.0 release (Unleash#199)

* 1.4.8

* docs: add maintenance mode (Unleash#202)

* Remove duplicate note (plus broken link) (Unleash#203)

* Bumped express to version 4.21.2.  This was required to resolve CVE-2024-52798 on path-to-regexp package. (Unleash#205)

Co-authored-by: stefano <stefano@zebedee.io>

* 1.4.9

* fix: deps

---------

Co-authored-by: Christopher Kolstad <chriswk@getunleash.io>
Co-authored-by: Fredrik Strand Oseberg <fredrik.no@gmail.com>
Co-authored-by: Melinda Fekete <melinda.fekete@getunleash.io>
Co-authored-by: spirrello <spirrello@users.noreply.github.com>
Co-authored-by: stefano <stefano@zebedee.io>
Co-authored-by: Gastón Fournier <gaston@getunleash.io>
* chore(ci): workflow permissions

* chore(ci): workflow permissions
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.11 to 1.1.12.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@1.1.11...v1.1.12)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.12
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [form-data](https://github.com/form-data/form-data) from 4.0.0 to 4.0.4.
- [Release notes](https://github.com/form-data/form-data/releases)
- [Changelog](https://github.com/form-data/form-data/blob/master/CHANGELOG.md)
- [Commits](form-data/form-data@v4.0.0...v4.0.4)

---
updated-dependencies:
- dependency-name: form-data
  dependency-version: 4.0.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…nsitive information (#10)

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Bumps [validator](https://github.com/validatorjs/validator.js) from 13.12.0 to 13.15.20.
- [Release notes](https://github.com/validatorjs/validator.js/releases)
- [Changelog](https://github.com/validatorjs/validator.js/blob/master/CHANGELOG.md)
- [Commits](validatorjs/validator.js@13.12.0...13.15.20)

---
updated-dependencies:
- dependency-name: validator
  dependency-version: 13.15.20
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [validator](https://github.com/validatorjs/validator.js) from 13.15.20 to 13.15.23.
- [Release notes](https://github.com/validatorjs/validator.js/releases)
- [Changelog](https://github.com/validatorjs/validator.js/blob/master/CHANGELOG.md)
- [Commits](validatorjs/validator.js@13.15.20...13.15.23)

---
updated-dependencies:
- dependency-name: validator
  dependency-version: 13.15.23
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [qs](https://github.com/ljharb/qs) from 6.13.0 to 6.14.1.
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.13.0...v6.14.1)

---
updated-dependencies:
- dependency-name: qs
  dependency-version: 6.14.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* build(deps): bump qs from 6.13.0 to 6.14.1

Bumps [qs](https://github.com/ljharb/qs) from 6.13.0 to 6.14.1.
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.13.0...v6.14.1)

---
updated-dependencies:
- dependency-name: qs
  dependency-version: 6.14.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix: update lock file

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Jan Mooij <jan.mooij@commercetools.com>
@robmonct robmonct closed this Feb 3, 2026
@github-project-automation github-project-automation bot moved this from New to Done in Issues and PRs Feb 3, 2026
@robmonct robmonct deleted the robmonct/fix_critical_vuln branch February 3, 2026 10:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants