Skip to content

fix: Upgrade npm dependencies#385

Merged
aswinayyolath merged 1 commit intoibm-messaging:masterfrom
ladeedanasreen:semver
Feb 13, 2026
Merged

fix: Upgrade npm dependencies#385
aswinayyolath merged 1 commit intoibm-messaging:masterfrom
ladeedanasreen:semver

Conversation

@ladeedanasreen
Copy link
Copy Markdown
Contributor

@ladeedanasreen ladeedanasreen commented Feb 13, 2026

This PR updates the following dependencies of npm using the overrides field in package.json:

Updates async to 3.2.2, which fixes the vulnerability CVE-2021-43138
Updates got to 11.8.5, which fixes the vulnerability CVE-2022-33987
Updates micromatch to 4.0.8, which fixes the vulnerability CVE-2024-4067
Updates @babel/runtime to 7.26.10, which fixes the vulnerability CVE-2025-27789
Updates lodash-es to 4.17.23 (direct dependency), which fixes the vulnerability CVE-2025-13465
Closes: #384

Signed-off-by: Ladeeda Nasreen P ladeedanasreen@ibm.com

Closes: ibm-messaging#384
Signed-off-by: Ladeeda Nasreen P <ladeedanasreen@ibm.com>
@ladeedanasreen
Copy link
Copy Markdown
Contributor Author

Tested starter app UI after changes
Screenshot 2026-02-13 at 12 22 47 PM

@aswinayyolath aswinayyolath merged commit 5d467d8 into ibm-messaging:master Feb 13, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix security vulnerabilities

3 participants