Skip to content

fix(deps): patch runtime dependency vulnerabilities - #2

Merged
Starosdev merged 1 commit into
developfrom
codex/sonarr-dependabot-batch
Jul 14, 2026
Merged

Starosdev merged 1 commit into
developfrom
codex/sonarr-dependabot-batch

Conversation

@Starosdev

Copy link
Copy Markdown
Owner

Summary

  • Upgrade direct lodash and qs runtime dependencies to patched releases.
  • Resolve ws and immutable transitive paths to patched releases in both lockfiles.
  • Use lodash 4.18.1 because npm marks 4.18.0 as a bad release.

Validation

  • yarn install --frozen-lockfile --ignore-scripts
  • yarn build
  • yarn lint
  • yarn stylelint

This PR is the first Sonarr runtime batch. Remaining Dependabot alerts are outside this focused change.

@Starosdev
Starosdev merged commit e2f8d7f into develop Jul 14, 2026
4 checks passed
@Starosdev
Starosdev deleted the codex/sonarr-dependabot-batch branch July 14, 2026 14:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant