Skip to content

chore: fix high-severity dev-dependency vulnerabilities - #336

Open
Ravandevil25 wants to merge 1 commit into
extrabacon:masterfrom
Ravandevil25:chore/fix-dev-dep-vulns
Open

Ravandevil25 wants to merge 1 commit into
extrabacon:masterfrom
Ravandevil25:chore/fix-dev-dep-vulns

Conversation

@Ravandevil25

Copy link
Copy Markdown

Summary

Upgrades mocha 11.7.5 → 12.0.2, eliminating all 6 npm audit findings — including the high-severity serialize-javascript RCE advisories (GHSA-5c6j-r48x-rmvq, GHSA-qj8w-gfj5-8c6v) pulled in via the dev test chain.

Scope

  • package.json: single version bump, dev-only.
  • package-lock.json: regenerated accordingly.
  • Production code untouched (index.ts identical).

Verification

  • npx tsc -p ./ — passes.
  • Full suite npx mocha -r ts-node/register — 43/43 passing (Node + Python 3.14).
  • npm audit — 0 vulnerabilities (was 6: 1 low, 1 moderate, 4 high).

Related context: dependency-refresh part of the maintenance backlog; offered as proof-of-work alongside my co-maintainer application in #290.

Upgrade mocha 11.7.5 to 12.0.2, eliminating 6 audit findings
including serialize-javascript RCE advisories
(GHSA-5c6j-r48x-rmvq, GHSA-qj8w-gfj5-8c6v).

Verified: tsc build passes, full suite 43/43 passing on
Node + Python 3.14. Production code untouched.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant