fix(deps): resolve high-severity rollup vulnerability in docs-site#1069
fix(deps): resolve high-severity rollup vulnerability in docs-site#1069
Conversation
Co-authored-by: Mossaka <5447827+Mossaka@users.noreply.github.com>
✅ Coverage Check PassedOverall Coverage
📁 Per-file Coverage Changes (1 files)
Coverage comparison generated by |
There was a problem hiding this comment.
Copilot wasn't able to review any files in this pull request.
Files not reviewed (1)
- docs-site/package-lock.json: Language not supported
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
C++ Build Test Results
Overall: PASS ✅
|
🦕 Deno Build Test Results
Overall: ✅ PASS All Deno tests passed successfully (Deno 2.7.1).
|
|
Smoke Test Results — PASS
|
.NET Build Test Results
Overall: PASS ✅ Run outputhello-world:
|
Smoke Test Results — Copilot Engine ✅ PASS
PR author:
|
Go Build Test Results
Overall: ✅ PASS
|
Bun Build Test Results
Overall: PASS ✅ Tested with Bun v1.3.10
|
🦀 Rust Build Test Results
Overall: ✅ PASS
|
Java Build Test Results
Overall: PASS ✅ All projects compiled and all tests passed successfully.
|
|
PR titles: chore(deps-dev): bump minimatch from 10.2.1 to 10.2.4 | Completing task
|
Node.js Build Test Results
Overall: ✅ PASS
|
CI "Dependency Vulnerability Audit" fails because
npm audit --audit-level=highcatches GHSA-mw96-cpmx-2vgc (arbitrary file write via path traversal in rollup 4.0.0–4.58.0).npm audit fixindocs-site/— updatespackage-lock.jsononly, no breaking changesrollupvulnerability plus moderatelodash-es,devalue, andajvadvisorieslodashvulnerabilities (via@astrojs/check→volar-service-yaml→yaml-language-server) require a breaking@astrojs/checkupgrade and don't trip--audit-level=highOriginal prompt
🔒 GitHub Advanced Security automatically protects Copilot coding agent pull requests. You can protect all pull requests by enabling Advanced Security for your repositories. Learn more about Advanced Security.