Skip to content

Fix security dependency alerts and CodeQL findings#104

Merged
hmmhmmhm merged 2 commits into
mainfrom
fix/security-deps-codeql
Jun 21, 2026
Merged

Fix security dependency alerts and CodeQL findings#104
hmmhmmhm merged 2 commits into
mainfrom
fix/security-deps-codeql

Conversation

@hmmhmmhm

Copy link
Copy Markdown
Owner

Summary

  • update dependency ranges and transitive overrides to clear npm audit security findings
  • include Dependabot PR updates for hono, proj4, wrangler, biome, prettier, eslint, sharp, node/workers types, and typescript-eslint
  • migrate Biome config to 2.5.0 schema
  • fix CodeQL HTML sanitization findings in Naver local place normalization

Security coverage

  • hono patched to 4.12.26
  • tmp override patched to 0.2.7
  • undici override patched to 7.28.0
  • markdown-it override patched to 14.2.0
  • esbuild override patched to 0.28.1
  • ws override patched to 8.21.0
  • wrangler patched to 4.103.0

Verification

  • npm audit --json reports 0 vulnerabilities
  • npm test -- tests/services/places/client.test.ts
  • npm test -- tests/scripts/repository-config.test.ts tests/services/places/client.test.ts
  • npm run lint:biome
  • npm run check
  • npm run build

@hmmhmmhm hmmhmmhm force-pushed the fix/security-deps-codeql branch from 8730d8d to 40f2cd9 Compare June 21, 2026 07:33
@hmmhmmhm

Copy link
Copy Markdown
Owner Author

Reopening to retrigger checks on the latest head SHA.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant