Skip to content

fix(deps): resolve Dependabot security alerts - #1981

Open
anwesham-lab wants to merge 1 commit into
mainfrom
security/resolve-dependabot-alerts-2026-10-02
Open

anwesham-lab wants to merge 1 commit into
mainfrom
security/resolve-dependabot-alerts-2026-10-02

Conversation

@anwesham-lab

Copy link
Copy Markdown
Contributor

Resolve the actionable Dependabot security alerts across sample lockfiles.

  • update mysql2 to 3.24.5
  • update rustls-webpki to 0.103.13
  • force Drizzle samples onto patched esbuild 0.25.12
  • pin Sequelize transitive uuid to patched CommonJS-compatible 11.1.1
  • update aws-cdk-lib to the latest 2.272.0 bundle

Validation:

  • Drizzle install/build passed; npm audit reports zero
  • both Sequelize clean installs and CommonJS uuid smoke tests passed; TypeScript sample builds
  • Prisma lock audit reports zero; full install is blocked locally by an unrelated uncached package
  • Rust lock update was resolved; full tests are blocked locally by an uncached arc-swap crate
  • Lambda clean install passed

Known upstream limit: latest aws-cdk-lib still bundles vulnerable brace-expansion 5.0.x, so its remaining alerts cannot be resolved by npm overrides; they require a patched CDK release.

@anwesham-lab
anwesham-lab enabled auto-merge (squash) October 2, 2026 17:00

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant