0.11.0 Dependency Updates #531

Open
opened 2026-09-15 18:29:20 +01:00 by Vylpes · 1 comment
Owner

Investigate what dependencies need updating, update the non-breaking changes, create new tickets for breaking changes and milestone to this release. yarn audit should return 0 vulnerabilities`

Investigate what dependencies need updating, update the non-breaking changes, create new tickets for breaking changes and milestone to this release. `yarn audit` should return 0 vulnerabilities`
Vylpes added this to the 0.11.0 milestone 2026-09-15 18:29:20 +01:00
Vylpes added this to the 0.10 Sprint 4 project 2026-09-23 18:40:18 +01:00
Vylpes self-assigned this 2026-10-04 18:16:53 +01:00
Member

Update

Non-breaking dependency updates are ready on branch feature/531-dependency-updates (commit pending local GPG signing).

Done

  • Upgraded non-breaking deps within current majors (discord.js, axios, jest, typescript-eslint, etc.)
  • Patched typeorm 0.3.28 → 0.3.31 (security)
  • Added/updated yarn resolutions for transitive advisories
  • Vendored temporary [email protected] backport (CVE-2026-93687 / GHSA-vfj7-8cjw-p6xm) until upstream publishes
  • yarn audit → 0 vulnerabilities
  • yarn build, yarn test, yarn lint pass

Breaking-change tickets (milestone 0.11.0)

  • #556 Upgrade dotenv v16 → v18
  • #557 Upgrade eslint v9 → v10
  • #558 Upgrade np v10 → v12
  • #559 Upgrade TypeScript v5 → v7
  • #560 Upgrade @types/node v24 → v26
  • #561 Upgrade @types/uuid v10 → v11
  • #562 Upgrade TypeORM 0.3.x → 1.x
  • #563 Remove vendored braces once upstream publishes a patched release
## Update Non-breaking dependency updates are ready on branch `feature/531-dependency-updates` (commit pending local GPG signing). ### Done - Upgraded non-breaking deps within current majors (discord.js, axios, jest, typescript-eslint, etc.) - Patched `typeorm` `0.3.28` → `0.3.31` (security) - Added/updated yarn resolutions for transitive advisories - Vendored temporary `[email protected]` backport (CVE-2026-93687 / GHSA-vfj7-8cjw-p6xm) until upstream publishes - `yarn audit` → **0 vulnerabilities** - `yarn build`, `yarn test`, `yarn lint` pass ### Breaking-change tickets (milestone **0.11.0**) - #556 Upgrade dotenv v16 → v18 - #557 Upgrade eslint v9 → v10 - #558 Upgrade np v10 → v12 - #559 Upgrade TypeScript v5 → v7 - #560 Upgrade @types/node v24 → v26 - #561 Upgrade @types/uuid v10 → v11 - #562 Upgrade TypeORM 0.3.x → 1.x - #563 Remove vendored braces once upstream publishes a patched release
Vylpes stopped working 2026-10-04 18:31:23 +01:00
14 minutes 24 seconds
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Total time spent: 14 minutes 24 seconds
Vylpes
14 minutes 24 seconds
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
External/card-drop#531
No description provided.