Skip to content

pnpm dependency update 2026-08-17 - #208

Closed
commercelayer-ci wants to merge 1 commit into
mainfrom
chore/deps-update-202608171005
Closed

pnpm dependency update 2026-08-17#208
commercelayer-ci wants to merge 1 commit into
mainfrom
chore/deps-update-202608171005

Conversation

@commercelayer-ci

Copy link
Copy Markdown
Contributor

Dependency update

Closes #207
Branch: chore/deps-update-202608171005
Based on stable: v6.9.5
Prerelease tag: v6.9.6-auto-deps-202608171005.0
Node.js: 20.x
pnpm: 10.x

Automated dependency update via pnpm. Review the dependency diff and validation output before merging.

Dependency update results

  • Check: success
  • Build: success
  • Test: failure
Test output

Semver bump log

package.json
  @biomejs/biome                ^2.5.2  →    ^2.5.8
  @commercelayer/cli-core      ^5.11.1  →   ^5.11.3
  @commercelayer/cli-dev        ^3.1.5  →    ^3.1.9
  @commercelayer/cli-ux         ^1.2.1  →    ^1.2.3
  @oclif/plugin-autocomplete   ^3.2.53  →   ^3.2.56
  @oclif/plugin-help           ^6.2.53  →   ^6.2.58
  @oclif/plugin-not-found      ^3.2.88  →   ^3.2.93
  @oclif/plugin-plugins        ^5.4.81  →   ^5.4.87
  @types/node                  ^25.9.4  →   ^25.9.5
  oclif                       ^4.23.24  →  ^4.23.30
  prettier                      ^3.9.4  →    ^3.9.6
  semantic-release             ^25.0.5  →   ^25.0.9
  tsx  ^4.22.4  →  ^4.23.12

Audit log

┌─────────────────────┬────────────────────────────────────────────────────────┐
│ high                │ Serialize JavaScript is Vulnerable to RCE via          │
│                     │ RegExp.flags and Date.prototype.toISOString()          │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ serialize-javascript                                   │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ <=7.0.2                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=7.0.3                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>mocha>serialize-javascript                           │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-5c6j-r48x-rmvq      │
└─────────────────────┴────────────────────────────────────────────────────────┘
┌─────────────────────┬────────────────────────────────────────────────────────┐
│ moderate            │ Serialize JavaScript has CPU Exhaustion Denial of      │
│                     │ Service via crafted array-like objects                 │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Package             │ serialize-javascript                                   │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Vulnerable versions │ >=5.0.0 <7.0.5                                         │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Patched versions    │ >=7.0.5                                                │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ Paths               │ .>mocha>serialize-javascript                           │
├─────────────────────┼────────────────────────────────────────────────────────┤
│ More info           │ https://github.com/advisories/GHSA-qj8w-gfj5-8c6v      │
└─────────────────────┴────────────────────────────────────────────────────────┘
2 vulnerabilities found
Severity: 1 moderate | 1 high

Major updates log not updated

package.json
  @commercelayer/sdk           ^6.58.0  →  ^7.12.1
  @oclif/core                  ^3.27.0  →  ^4.13.5
  @oclif/test                  ^3.2.15  →  ^4.1.22
  @semantic-release/changelog   ^6.0.3  →   ^7.0.0
  @semantic-release/git        ^10.0.1  →  ^11.0.1
  @types/configstore            ^4.0.0  →   ^6.0.2
  @types/inquirer              ^8.2.13  →  ^9.0.10
  @types/node                  ^25.9.5  →  ^26.2.0
  @types/update-notifier        ^5.1.0  →   ^6.0.8
  configstore                   ^5.0.1  →   ^8.0.0
  inquirer                      ^8.2.7  →  ^14.0.2
  mocha                        ^10.8.2  →  ^11.8.0
  typescript                    ^5.9.3  →   ^7.0.2

@commercelayer-ci commercelayer-ci added the dependencies Pull requests that update a dependency file label Aug 17, 2026
@commercelayer-ci commercelayer-ci self-assigned this Aug 17, 2026
@commercelayer-ci commercelayer-ci added the dependencies Pull requests that update a dependency file label Aug 17, 2026
@pviti pviti closed this Aug 17, 2026
@pviti
pviti deleted the chore/deps-update-202608171005 branch August 17, 2026 16:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[VANTA] [VULNERABILITY] <HIGH> CVE-2026-14257, CVE-2026-69152, GHSA-5p4m-2wfm-xmqj, fix before 2026-08-31

2 participants