Skip to content

fix: resolve security vulnerabilities through updated deps#1350

Merged
jbroma merged 5 commits intomainfrom
fix/update-outdated-dependencies
Feb 26, 2026
Merged

fix: resolve security vulnerabilities through updated deps#1350
jbroma merged 5 commits intomainfrom
fix/update-outdated-dependencies

Conversation

@jbroma
Copy link
Member

@jbroma jbroma commented Feb 26, 2026

Summary

Test plan

  • pnpm install succeeds
  • pnpm build passes (all packages)
  • pnpm test passes (28 suites, 243 tests)
  • Lockfile confirms patched versions: jws@4.0.1, webpack@5.105.3, @rsdoctor/rspack-plugin@1.5.2

🤖 Generated with Claude Code

jbroma and others added 2 commits February 26, 2026 13:46
…alerts

- Update webpack catalog ^5.99.9 → ^5.104.1 (fixes CVE alerts #469, #470)
- Update jsonwebtoken ^9.0.2 → ^9.0.3 to resolve jws vulnerability (#452)
- Update @rsdoctor/rspack-plugin ^0.4.x → ^1.5.2 in tester apps to
  resolve lodash (#461) and qs (#453, #472) vulnerabilities

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@vercel
Copy link

vercel bot commented Feb 26, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
repack-website Ready Ready Preview, Comment Feb 26, 2026 1:57pm

Request Review

@changeset-bot
Copy link

changeset-bot bot commented Feb 26, 2026

🦋 Changeset detected

Latest commit: 3514ed3

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 6 packages
Name Type
@callstack/repack Patch
@callstack/repack-plugin-expo-modules Patch
@callstack/repack-plugin-nativewind Patch
@callstack/repack-plugin-reanimated Patch
@callstack/repack-dev-server Patch
@callstack/repack-init Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

jbroma and others added 2 commits February 26, 2026 14:51
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@jbroma jbroma merged commit b083b9d into main Feb 26, 2026
5 checks passed
@jbroma jbroma deleted the fix/update-outdated-dependencies branch February 26, 2026 14:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant