fix: Security updates #36
Merged
StepSecurity Actions Security / StepSecurity Required Checks
succeeded
Nov 17, 2025 in 2s
StepSecurity Required Checks
Finished StepSecurity Required Checks
- Pwn Request Vulnerabilities Check - Checks for Pwn Request vulnerabilities in the PR via risky triggers
- Script Injection Check - Checks for script injection vulnerabilities in the PR
- NPM Compromised Packages Check - Checks for compromised npm package versions in the PR
- NPM Package Cooldown Check - Fails if any package version in the PR was released within the configured cooldown period, helping to avoid brand-new (and potentially unreviewed or malicious) releases
Details
✅ Pwn Request Vulnerabilities Check
No Pwn Request vulnerabilities found in this PR.
✅ Script Injection Vulnerabilities Check
No Script Injection vulnerabilities found in this PR.
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
✅ NPM Package Cooldown Check
No npm package upgrades to recent releases found in current PR.
The following npm packages are inspected in current PR
| Package Name | Previous Version | Current Version | file | Current Version Release Date |
|---|---|---|---|---|
| js-yaml | 4.1.0 | 4.1.1 | package-lock.json | 2025-11-12T15:18:03Z |
| ts-jest | 29.1.0 | 29.4.5 | package-lock.json | 2025-10-10T10:05:43Z |
| type-fest | 4.41.0 | package-lock.json | 2025-05-06T07:20:19Z | |
| uglify-js | 3.19.3 | package-lock.json | 2024-08-29T13:49:01Z | |
| handlebars | 4.7.8 | package-lock.json | 2023-08-01T21:19:12Z | |
| neo-async | 2.6.2 | package-lock.json | 2020-07-09T18:23:53Z | |
| wordwrap | 1.0.0 | package-lock.json | 2015-05-07T17:07:25Z |
⏲️ History
Previous invocation results of same check:
✅ Pwn Request Vulnerabilities Check
No Pwn Request vulnerabilities found in this PR.
✅ Script Injection Vulnerabilities Check
No Script Injection vulnerabilities found in this PR.
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
✅ NPM Package Cooldown Check
No npm package upgrades to recent releases found in current PR.
The following npm packages are inspected in current PR
| Package Name | Previous Version | Current Version | file | Current Version Release Date |
|---|---|---|---|---|
| js-yaml | 4.1.0 | 4.1.1 | package-lock.json | 2025-11-12T15:18:03Z |
| ts-jest | 29.1.0 | 29.4.5 | package-lock.json | 2025-10-10T10:05:43Z |
| type-fest | 4.41.0 | package-lock.json | 2025-05-06T07:20:19Z | |
| uglify-js | 3.19.3 | package-lock.json | 2024-08-29T13:49:01Z | |
| handlebars | 4.7.8 | package-lock.json | 2023-08-01T21:19:12Z | |
| neo-async | 2.6.2 | package-lock.json | 2020-07-09T18:23:53Z | |
| wordwrap | 1.0.0 | package-lock.json | 2015-05-07T17:07:25Z |
⏲️ History
Previous invocation results of same check:
Loading