Skip to content

Update web-console and docs.feldera.com deps to avoid vulnerabilities#5685

Merged
Karakatiza666 merged 1 commit intomainfrom
update-deps
Feb 25, 2026
Merged

Update web-console and docs.feldera.com deps to avoid vulnerabilities#5685
Karakatiza666 merged 1 commit intomainfrom
update-deps

Conversation

@Karakatiza666
Copy link
Contributor

@Karakatiza666 Karakatiza666 commented Feb 24, 2026

@Karakatiza666 Karakatiza666 requested a review from gz February 24, 2026 10:01
Copy link
Collaborator

@mythical-fred mythical-fred left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — clean security dep update. A few notes for context:

  • ajv@6.14.0 is the official legacy dist-tag on npm — a real security backport for the 6.x line, so the overrides are correct.
  • Removing jsonpath entirely is the right call; it has prototype-pollution history and is effectively unmaintained.
  • minimatch, fast-xml-parser, svelte, vite bumps all look purposeful and scoped to the Dependabot alerts.
  • No unexpected non-security churn in the diffs.

Minor (non-blocking): future security fix commits could include Fixes #187, #188, #189 in the commit body to link the Dependabot alerts into the linear history — makes archaeology easier. Not a blocker here.

Copy link
Contributor

@gz gz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks for doing this

@gz gz added this pull request to the merge queue Feb 24, 2026
@github-merge-queue github-merge-queue bot removed this pull request from the merge queue due to failed status checks Feb 24, 2026
Signed-off-by: Karakatiza666 <bulakh.96@gmail.com>
@Karakatiza666 Karakatiza666 added this pull request to the merge queue Feb 25, 2026
Merged via the queue into main with commit b23449a Feb 25, 2026
1 check passed
@Karakatiza666 Karakatiza666 deleted the update-deps branch February 25, 2026 15:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants