Skip to content

fix(deps): remediate remaining security alerts - #3

Merged
Starosdev merged 1 commit into
developfrom
codex/sonarr-dependabot-remaining
Jul 14, 2026
Merged

Starosdev merged 1 commit into
developfrom
codex/sonarr-dependabot-remaining

Conversation

@Starosdev

Copy link
Copy Markdown
Owner

Summary

  • update direct frontend dependency families and refresh Yarn and pnpm lockfiles
  • pin patched transitive versions for the remaining Dependabot families
  • update MailKit to 4.16.0 and SixLabors.ImageSharp to 3.1.11

Validation

  • yarn audit --level high
  • pnpm audit, no high findings
  • yarn build
  • yarn lint
  • yarn stylelint
  • dotnet restore with SDK 8.0.422 for local validation
  • dotnet build with analyzers disabled

Known notes: the checked-in global.json still pins SDK 6.0.405, which is not installed locally. The normal SDK 8 analyzer pass reports existing SA1200 findings across the baseline; the compile-only build passes.

@Starosdev
Starosdev merged commit d91b2dc into develop Jul 14, 2026
4 checks passed
@Starosdev
Starosdev deleted the codex/sonarr-dependabot-remaining branch July 14, 2026 16:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant