close
Skip to content

Run npm audit fix#1274

Merged
rzhao271 merged 1 commit into
mainfrom
copilot/run-npm-audit-fix
May 14, 2026
Merged

Run npm audit fix#1274
rzhao271 merged 1 commit into
mainfrom
copilot/run-npm-audit-fix

Conversation

Copy link
Copy Markdown
Contributor

Copilot AI commented May 14, 2026

Summary

  • Ran npm audit fix in the repository
  • Updated package-lock.json to apply available non-breaking fixes
  • Upgraded brace-expansion from 5.0.3 to 5.0.6

Validation

  • npm run build
  • npm test
  • parallel_validation (Code Review + CodeQL)

Notes

  • npm audit fix still reports 2 low-severity vulnerabilities in mocha's transitive diff dependency with no non-breaking fix currently applied by npm audit.

Agent-Logs-Url: https://github.com/microsoft/vscode-vsce/sessions/f2316742-5e81-44c7-ad59-2785c896ae92

Co-authored-by: rzhao271 <7199958+rzhao271@users.noreply.github.com>
@rzhao271 rzhao271 added this to the 1.121.0 milestone May 14, 2026
@rzhao271 rzhao271 marked this pull request as ready for review May 14, 2026 00:05
@rzhao271 rzhao271 enabled auto-merge (squash) May 14, 2026 00:05
@rzhao271 rzhao271 merged commit 4699582 into main May 14, 2026
5 checks passed
@rzhao271 rzhao271 deleted the copilot/run-npm-audit-fix branch May 14, 2026 00:11
adrianstephens pushed a commit to adrianstephens/vscode-vsce that referenced this pull request Jun 3, 2026
Agent-Logs-Url: https://github.com/microsoft/vscode-vsce/sessions/f2316742-5e81-44c7-ad59-2785c896ae92

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: rzhao271 <7199958+rzhao271@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants