Skip to content

aegis: dependency fix (GHSA-4633-3j49-mh5q) - #2

Open
tiXor-code wants to merge 1 commit into
mainfrom
fix/aegis-deps-11909232
Open

tiXor-code wants to merge 1 commit into
mainfrom
fix/aegis-deps-11909232

Conversation

@tiXor-code

Copy link
Copy Markdown
Owner

Automated dependency-vulnerability fix from Aegis.

Finding: next 16.2.9: GHSA-4633-3j49-mh5q
Ref: GHSA-4633-3j49-mh5q

Applied the semver-safe audit fix (no --force). Please review the lockfile diff and let CI run before merging.

Fingerprint 11909232adeb06da.

@vercel

vercel Bot commented Jul 27, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
eve-arbitrage Ready Ready Preview, Comment Jul 27, 2026 6:48am

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified: change is lockfile-only (package-lock.json), no package.json edits. next bumped 16.2.9→16.2.12 and the tailwindcss toolchain (tailwindcss/@tailwindcss/postcss/oxide/node) 4.3.1→4.3.3 plus postcss/nanoid/enhanced-resolve, all still within the existing caret ranges in package.json. No source code, config, or test changes, so no test updates were needed. This is a semver-safe audit fix consistent with the stated GHSA-4633-3j49-mh5q remediation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant