Skip to content

fix: upgrade vulnerable direct dependencies - #6153

Merged
colinhacks merged 4 commits into
colinhacks:mainfrom
sonukapoor:fix/upgrade-vulnerable-direct-deps
Sep 12, 2026
Merged

colinhacks merged 4 commits into
colinhacks:mainfrom
sonukapoor:fix/upgrade-vulnerable-direct-deps

Conversation

@sonukapoor

Copy link
Copy Markdown
Contributor

This upgrades two high-severity direct dependencies identified by the CVE Lite dependency audit in PR #6152.

next in packages/docs is upgraded from 15.5.15 to 15.5.18, and vite in the root workspace is upgraded from 7.3.2 to 7.3.5. Both are the minimum safe versions confirmed by the OSV advisory database. The scan found 25 total findings across the lockfile; these two are the direct dependencies where a targeted upgrade is possible without touching transitive parent chains.

All 339 test files and 3,811 tests pass after the upgrades. The pnpm lockfile is updated in the same commit.

@colinhacks
colinhacks merged commit f6e1701 into colinhacks:main Sep 12, 2026
7 checks passed

This branch was successfully deployed

1 active deployment
Preview – zod-v4 — f7c2fdb3 Deployed Sep 12, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants