fix: Security updates #28
+264
−224
Merged
StepSecurity Actions Security / StepSecurity Required Checks
succeeded
Feb 2, 2026 in 2s
StepSecurity Required Checks
Finished StepSecurity Required Checks
- Script Injection Check - Checks for script injection vulnerabilities in the PR
- NPM Compromised Packages Check - Checks for compromised npm package versions in the PR
- NPM Package Cooldown Check - Fails if any package version in the PR was released within the configured cooldown period, helping to avoid brand-new (and potentially unreviewed or malicious) releases
- Pwn Request Vulnerabilities Check - Checks for Pwn Request vulnerabilities in the PR via risky triggers
Details
✅ Script Injection Vulnerabilities Check
No Script Injection vulnerabilities found in this PR.
✅ Pwn Request Vulnerabilities Check
No Pwn Request vulnerabilities found in this PR.
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
✅ NPM Package Cooldown Check
No npm package upgrades to recent releases found in current PR.
The following npm packages are inspected in current PR
| Package Name | Previous Version | Current Version | file | Current Version Release Date |
|---|---|---|---|---|
| esquery | 1.4.0 | 1.7.0 | package-lock.json | 2025-12-31T15:44:57Z |
| @eslint-community/eslint-utils | 4.9.1 | package-lock.json | 2025-12-31T14:49:52Z | |
| @eslint-community/regexpp | 4.12.2 | package-lock.json | 2025-10-22T11:56:00Z | |
| acorn | 8.8.1 | 8.15.0 | package-lock.json | 2025-06-08T16:23:04Z |
| import-fresh | 3.3.0 | 3.3.1 | package-lock.json | 2025-02-02T09:45:41Z |
| @ungap/structured-clone | 1.3.0 | package-lock.json | 2025-01-23T14:13:01Z | |
| eslint | 8.26.0 | 8.57.1 | package-lock.json | 2024-09-16T15:20:44Z |
| @eslint/js | 8.57.1 | package-lock.json | 2024-09-16T14:48:48Z | |
| ignore | 5.2.0 | 5.3.2 | package-lock.json | 2024-08-12T08:51:00Z |
| optionator | 0.9.1 | 0.9.4 | package-lock.json | 2024-04-26T22:17:51Z |
| @humanwhocodes/config-array | 0.11.7 | 0.13.0 | package-lock.json | 2024-04-17T18:23:32Z |
| @humanwhocodes/object-schema | 1.2.1 | 2.0.3 | package-lock.json | 2024-04-01T20:31:25Z |
| globals | 13.17.0 | 13.24.0 | package-lock.json | 2023-12-10T17:32:48Z |
| @eslint/eslintrc | 1.3.3 | 2.1.4 | package-lock.json | 2023-12-01T21:03:13Z |
| punycode | 2.1.1 | 2.3.1 | package-lock.json | 2023-10-30T18:28:32Z |
| eslint-visitor-keys | 3.3.0 | 3.4.3 | package-lock.json | 2023-08-11T14:49:54Z |
| eslint-scope | 7.1.1 | 7.2.2 | package-lock.json | 2023-07-28T15:20:07Z |
| espree | 9.4.0 | 9.6.1 | package-lock.json | 2023-07-14T15:47:50Z |
| graphemer | 1.4.0 | package-lock.json | 2022-09-19T10:19:34Z | |
| deep-is | 0.1.3 | 0.1.4 | package-lock.json | 2021-09-04T16:55:20Z |
⏲️ History
Previous invocation results of same check:
✅ Script Injection Vulnerabilities Check
No Script Injection vulnerabilities found in this PR.
✅ Pwn Request Vulnerabilities Check
No Pwn Request vulnerabilities found in this PR.
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
✅ NPM Package Cooldown Check
No npm package upgrades to recent releases found in current PR.
The following npm packages are inspected in current PR
| Package Name | Previous Version | Current Version | file | Current Version Release Date |
|---|---|---|---|---|
| esquery | 1.4.0 | 1.7.0 | package-lock.json | 2025-12-31T15:44:57Z |
| @eslint-community/eslint-utils | 4.9.1 | package-lock.json | 2025-12-31T14:49:52Z | |
| @eslint-community/regexpp | 4.12.2 | package-lock.json | 2025-10-22T11:56:00Z | |
| acorn | 8.8.1 | 8.15.0 | package-lock.json | 2025-06-08T16:23:04Z |
| import-fresh | 3.3.0 | 3.3.1 | package-lock.json | 2025-02-02T09:45:41Z |
| @ungap/structured-clone | 1.3.0 | package-lock.json | 2025-01-23T14:13:01Z | |
| eslint | 8.26.0 | 8.57.1 | package-lock.json | 2024-09-16T15:20:44Z |
| @eslint/js | 8.57.1 | package-lock.json | 2024-09-16T14:48:48Z | |
| ignore | 5.2.0 | 5.3.2 | package-lock.json | 2024-08-12T08:51:00Z |
| optionator | 0.9.1 | 0.9.4 | package-lock.json | 2024-04-26T22:17:51Z |
| @humanwhocodes/config-array | 0.11.7 | 0.13.0 | package-lock.json | 2024-04-17T18:23:32Z |
| @humanwhocodes/object-schema | 1.2.1 | 2.0.3 | package-lock.json | 2024-04-01T20:31:25Z |
| globals | 13.17.0 | 13.24.0 | package-lock.json | 2023-12-10T17:32:48Z |
| @eslint/eslintrc | 1.3.3 | 2.1.4 | package-lock.json | 2023-12-01T21:03:13Z |
| punycode | 2.1.1 | 2.3.1 | package-lock.json | 2023-10-30T18:28:32Z |
| eslint-visitor-keys | 3.3.0 | 3.4.3 | package-lock.json | 2023-08-11T14:49:54Z |
| eslint-scope | 7.1.1 | 7.2.2 | package-lock.json | 2023-07-28T15:20:07Z |
| espree | 9.4.0 | 9.6.1 | package-lock.json | 2023-07-14T15:47:50Z |
| graphemer | 1.4.0 | package-lock.json | 2022-09-19T10:19:34Z | |
| deep-is | 0.1.3 | 0.1.4 | package-lock.json | 2021-09-04T16:55:20Z |
⏲️ History
Previous invocation results of same check:
Loading