Skip to content

chore(deps): bi-weekly security patch of critical vulnerabilities - #1005

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
security-patch/vulnerabilities
Open

chore(deps): bi-weekly security patch of critical vulnerabilities#1005
github-actions[bot] wants to merge 1 commit into
mainfrom
security-patch/vulnerabilities

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Scheduled Security Patch

This PR was automatically created by the bi-weekly scheduled security patching job.
It scans for dependency vulnerabilities and upgrades vulnerable packages to safe versions.

Changes:

  • Scanned Python packages with pip-audit and upgraded vulnerable ones using uv.
  • Scanned Node.js packages with pnpm audit and upgraded high/critical ones.
  • Regenerated requirements.lock and lockfiles to match.

🔍 Security Patch Risk Analysis & Breaking Changes

This analysis automatically maps direct dependency upgrades against our codebase to evaluate breaking change risks:

📦 Node.js (Frontend) (echo/frontend/package.json)

Package Upgrade Risk Level Usages in Codebase Guidance
react-router ^7.18.1 ➡️ ^7.18.2 PATCH (Safe) 127 files ✅ Standard bug/security patch. Extremely safe.

Please review the upgrades and run tests to ensure no regressions are introduced.

@github-actions github-actions Bot added dependencies Pull requests that update a dependency file security labels Aug 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants