fix: Security updates #40
Merged
StepSecurity Actions Security / StepSecurity Required Checks
succeeded
Jan 12, 2026 in 1s
StepSecurity Required Checks
Finished StepSecurity Required Checks
- Pwn Request Vulnerabilities Check - Checks for Pwn Request vulnerabilities in the PR via risky triggers
- Script Injection Check - Checks for script injection vulnerabilities in the PR
- NPM Compromised Packages Check - Checks for compromised npm package versions in the PR
- NPM Package Cooldown Check - Fails if any package version in the PR was released within the configured cooldown period, helping to avoid brand-new (and potentially unreviewed or malicious) releases
Details
✅ Pwn Request Vulnerabilities Check
No Pwn Request vulnerabilities found in this PR.
✅ Script Injection Vulnerabilities Check
No Script Injection vulnerabilities found in this PR.
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
✅ NPM Package Cooldown Check
No npm package upgrades to recent releases found in current PR.
The following npm packages are inspected in current PR
| Package Name | Previous Version | Current Version | file | Current Version Release Date |
|---|---|---|---|---|
| qs | 6.11.0 | 6.14.1 | package-lock.json | 2025-12-29T22:05:45Z |
| call-bound | 1.0.4 | package-lock.json | 2025-03-03T17:50:03Z | |
| object-inspect | 1.11.0 | 1.13.4 | package-lock.json | 2025-02-05T01:26:10Z |
| side-channel | 1.0.4 | 1.1.0 | package-lock.json | 2024-12-11T17:00:33Z |
| side-channel-weakmap | 1.0.2 | package-lock.json | 2024-12-11T05:39:11Z | |
| side-channel-map | 1.0.1 | package-lock.json | 2024-12-11T04:53:18Z | |
| side-channel-list | 1.0.0 | package-lock.json | 2024-12-10T20:20:25Z |
⏲️ History
Previous invocation results of same check:
✅ Script Injection Vulnerabilities Check
No Script Injection vulnerabilities found in this PR.
✅ Pwn Request Vulnerabilities Check
No Pwn Request vulnerabilities found in this PR.
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
✅ NPM Package Cooldown Check
No npm package upgrades to recent releases found in current PR.
The following npm packages are inspected in current PR
| Package Name | Previous Version | Current Version | file | Current Version Release Date |
|---|---|---|---|---|
| qs | 6.11.0 | 6.14.1 | package-lock.json | 2025-12-29T22:05:45Z |
| call-bound | 1.0.4 | package-lock.json | 2025-03-03T17:50:03Z | |
| object-inspect | 1.11.0 | 1.13.4 | package-lock.json | 2025-02-05T01:26:10Z |
| side-channel | 1.0.4 | 1.1.0 | package-lock.json | 2024-12-11T17:00:33Z |
| side-channel-weakmap | 1.0.2 | package-lock.json | 2024-12-11T05:39:11Z | |
| side-channel-map | 1.0.1 | package-lock.json | 2024-12-11T04:53:18Z | |
| side-channel-list | 1.0.0 | package-lock.json | 2024-12-10T20:20:25Z |
⏲️ History
Previous invocation results of same check:
Loading