Skip to content

chore(CP-12104): patch critical and high library dependencies - #3

Open
tannerhelton wants to merge 1 commit into
mainfrom
feature/cp-12104-dependency-security
Open

chore(CP-12104): patch critical and high library dependencies#3
tannerhelton wants to merge 1 commit into
mainfrom
feature/cp-12104-dependency-security

Conversation

@tannerhelton

Copy link
Copy Markdown
Member

Summary

Upgrade Vite to6.4.3 and patch vulnerable Lodash/Rollup and transitive tooling paths.

Scope

Update the dependency paths associated with the critical/high library findings returned by pup from the Datadog devops organization.

Out of scope

Deployment and release promotion.

Verification

Frozen npm install and TypeScript/production library build passed. Lint still rejects the existing Fast Refresh export warning in src/index.tsx:2.

The resolved lockfile was compared against the upstream advisory affected ranges for these Datadog findings. Datadog may continue to show the base-branch findings until this change is merged and rescanned.

UI evidence

No visual changes.

Related work

CP-12104 tracks the cross-repository remediation.

Co-authored-by: Codex <noreply@openai.com>
@tannerhelton
tannerhelton marked this pull request as ready for review September 3, 2026 23:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant