Skip to content

Conversation

@leftieFriele
Copy link
Contributor

Updating all dependencies, including an override on 'glob' to patch a security issue while awaiting it to be fixed in stream modules.

@leftieFriele leftieFriele marked this pull request as ready for review December 10, 2025 10:28
@leftieFriele
Copy link
Contributor Author

I did what @wkillerud suggested, and I added an override for glob to remove the audit issues.

@wkillerud
Copy link
Contributor

wkillerud commented Dec 10, 2025

Our users won't get that override though, I don't think. If the end-goal is to fix an npm audit warning about this module we still need to update any dependency that pulls it in 😿

fixing security issues in dependencies, we update a bunch of
dependencies with the ones listed below the most important:

- @eik/core
- @eik/service
- @eik/sink-memory
- fastify
- yargs
- semantic-release
@leftieFriele
Copy link
Contributor Author

Went the rounds and updated common, core and service to get rid of the audit errors 😅 💦

@leftieFriele leftieFriele self-assigned this Dec 11, 2025
@leftieFriele leftieFriele merged commit 7302910 into main Dec 11, 2025
6 checks passed
@leftieFriele leftieFriele deleted the dec-cleanup branch December 11, 2025 13:40
leftieFriele added a commit that referenced this pull request Dec 11, 2025
fixing security issues in dependencies, we update a bunch of
dependencies with the ones listed below the most important:

- @eik/core
- @eik/service
- @eik/sink-memory
- fastify
- yargs
- semantic-release

Co-authored-by: espen dalløkken <espen.dallokken@m10s.io>
github-actions bot pushed a commit that referenced this pull request Dec 11, 2025
## [3.1.29](v3.1.28...v3.1.29) (2025-12-11)

### Bug Fixes

* updating depedencies ([#670](#670)) ([30bb802](30bb802))
* updating depedencies ([#670](#670)) ([7302910](7302910))
@github-actions
Copy link

🎉 This PR is included in version 3.1.29 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants