2.5.0 Dependency Updates #268
Labels
No labels
blocked
duplicate
needs
approval
needs
criteria
needs
estimate
needs
tests
question
step
doing
step
review
step
testing
step
todo
step
uat
type
admin
type
alert
type
bug
type
change
type
defect
type
dependencies
type
epic
type
idea
type
incident
type
investigation
type
spike
type
story
won't fix
No project
No assignees
2 participants
Total time spent: 25 minutes 19 seconds
Due date
Vylpes
25 minutes 19 seconds
No due date set.
Dependencies
No dependencies set
Reference
RabbitLabs/random-bunny#268
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Dependency audit overview — release 2.5.0
Date: 2026-09-10
Branch:
release/2.5.0Package manager: Yarn Classic (v1.22.22)
Summary
yarn audittotal findingsAll known vulnerabilities were cleared with yarn
resolutionsplus within-range upgrades of direct dependencies. Non-vulnerable packages were then brought up to the latest versions allowed by existing semver ranges. Major-version bumps (e.g. ESLint 10, TypeScript 7, Commander 15) were left for separate follow-up.Phase 1 — Vulnerability fixes
Approach
yarn auditand deduplicated advisories by ID (54 unique).@yao-pkg/pkg,jest,eslint,np, etc.).resolutionsto pin patched transitive versions where parents had not yet absorbed fixes.Critical / high issues addressed
tar7.5.22tar-fs3.1.3minimatch9.0.9brace-expansion2.1.4(was^2.0.2)picomatch4.0.7glob13.0.6tmp0.2.7js-yaml4.3.2lodash4.18.1browserslist4.28.9ajv$data6.15.0@babel/core7.29.7@humanfs/node0.16.8@eslint/plugin-kit0.4.1flatted3.4.4Resolutions block (after)
Yarn may warn that some of these pins are outside a dependent’s declared range; that is intentional for security. Runtime verification:
yarn test,yarn build, andyarn lintall succeed after the pins.Phase 2 — Non-vulnerable package updates
Direct dependencies were updated to the latest within their existing major / caret ranges (
Current=Wantedinyarn outdated).Runtime dependencies
commander^14.0.0^14.0.3htmlparser2^10.0.0^10.1.0glob-parent^6.0.0got-cjs^12.5.4linqts^2.0.0Dev dependencies
@eslint/eslintrc^3.3.1^3.3.7@eslint/js^9.30.1^9.39.5@jest/globals^30.0.4^30.5.1@types/node^24.0.12^24.13.4@typescript-eslint/eslint-plugin^8.36.0^8.70.0@typescript-eslint/parser^8.36.0^8.70.0@yao-pkg/pkg^6.5.1^6.22.0eslint^9.30.1^9.39.5jest^30.0.4^30.5.1jest-mock-extended^4.0.0^4.0.1np^10.2.0^10.3.0ts-jest^29.4.0^29.4.12typescript^5.8.3^5.9.3typescript-eslint^8.36.0^8.70.0Deferred major upgrades
These have newer majors available and were not applied in this pass. Tracked under milestone 2.6.0:
commanderhtmlparser2linqtseslint/@eslint/jsnptypescriptVerification
Commands run after the changes:
Files changed
package.json— dependency range bumps + expandedresolutionsyarn.lock— regenerated lockfiledocs/dependency-audit-2.5.0.md— this overview