Skip to content

fix(root): resolve high liquidjs vulnerability#10263

Merged
scopsy merged 1 commit intonextfrom
cursor/dependency-vulnerability-fix-9c17
Mar 12, 2026
Merged

fix(root): resolve high liquidjs vulnerability#10263
scopsy merged 1 commit intonextfrom
cursor/dependency-vulnerability-fix-9c17

Conversation

@cursor
Copy link
Contributor

@cursor cursor bot commented Mar 12, 2026

Updates liquidjs from ^10.20.0 to ^10.25.0 across all workspaces to fix a high severity vulnerability (GHSA-wmfp-5q7x-987x).

Fix strategy: Direct dependency update (non-breaking semver-compatible change within major version 10).

Affected workspaces:

  • apps/api
  • apps/dashboard
  • libs/application-generic
  • packages/framework
  • enterprise/packages/translation

Validation:

  • pnpm audit confirms advisory 1114299 is no longer present
  • pnpm build:v2 passes successfully
Open in Web View Automation 

Update liquidjs from ^10.20.0 to ^10.25.0 across all workspaces to address
a high severity vulnerability (GHSA-wmfp-5q7x-987x).

Advisory: GHSA-wmfp-5q7x-987x
Strategy: Direct dependency update (non-breaking semver-compatible change)
Affected workspaces: apps/api, apps/dashboard, libs/application-generic,
packages/framework, enterprise/packages/translation

Co-authored-by: Dima Grossman <dima@grossman.io>
@netlify
Copy link

netlify bot commented Mar 12, 2026

Deploy preview added

Name Link
🔨 Latest commit af7068d
🔍 Latest deploy log https://app.netlify.com/projects/dashboard-v2-novu-staging/deploys/69b269ba803b5000073b0214
😎 Deploy Preview https://deploy-preview-10263.dashboard-v2.novu-staging.co
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@github-actions
Copy link
Contributor

Hey there and thank you for opening this pull request! 👋

We require pull request titles to follow specific formatting rules and it looks like your proposed title needs to be adjusted.

Your PR title is: fix(root): resolve high liquidjs vulnerability

Requirements:

  1. Follow the Conventional Commits specification
  2. As a team member, include Linear ticket ID at the end: fixes TICKET-ID or include it in your branch name

Expected format: feat(scope): Add fancy new feature fixes NOV-123

Details:

PR title must end with 'fixes TICKET-ID' (e.g., 'fixes NOV-123') or include ticket ID in branch name

@scopsy scopsy marked this pull request as ready for review March 12, 2026 09:41
@scopsy scopsy merged commit d020b60 into next Mar 12, 2026
31 checks passed
@scopsy scopsy deleted the cursor/dependency-vulnerability-fix-9c17 branch March 12, 2026 09:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants