fix(deps): vuln minor upgrades — 15 packages (minor: 1 · patch: 14) #29
Conversation
Release Notesstorybook (8.6.15 → 8.6.18) — GitHub Releasev8.6.188.6.18
v8.6.178.6.17
v8.6.168.6.16
vite (6.4.1 → 6.4.2) — GitHub ReleasePlease refer to CHANGELOG.md for details. @axe-core/playwright (4.11.0 → 4.11.2) — GitHub Releasev4.11.2Bug Fixes
v4.11.1Bug Fixes
@babel/core (7.28.5 → 7.28.6) — GitHub Releasev7.28.6 (2026-01-12)Thanks @kadhirash and @kolvian for your first PRs! 🐛 Bug Fix
💅 Polish
🏠 Internal
🏃♀️ Performance
Committers: 7
(truncated — see source for full notes) @codemirror/autocomplete (6.20.0 → 6.20.1) — ChangelogBug fixesClicking the horizontal dots at the top/bottom of a list of completion options now moves the selection there, so that more completions become visible. @codemirror/commands (6.10.1 → 6.10.3) — ChangelogBug fixesMake sure selection-extending commands preserve the associativity of the selection head. @codemirror/state (6.5.2 → 6.5.4) — ChangelogBug fixesMake @codemirror/view (6.39.4 → 6.39.17) — ChangelogBug fixesImprove touch tap-selection on line wrapping boundaries. Make Fix an issue where @eslint/js (9.39.2 → 9.39.4) — GitHub Releasev9.39.4Bug Fixes
Documentation
Chores
v9.39.3Bug Fixes
Chores
@storybook/addon-a11y (8.6.15 → 8.6.18) — GitHub Releasev8.6.188.6.18
v8.6.178.6.17
v8.6.168.6.16
@storybook/addon-actions (8.6.15 → 8.6.18) — GitHub Releasev8.6.188.6.18
v8.6.178.6.17
v8.6.168.6.16
@storybook/addon-docs (8.6.15 → 8.6.18) — GitHub Releasev8.6.188.6.18
v8.6.178.6.17
v8.6.168.6.16
@storybook/addon-essentials (8.6.14 → 8.6.18) — GitHub Releasev8.6.188.6.18
v8.6.178.6.17
v8.6.168.6.16
v8.6.158.6.15
Generated by ADMS Sources: 9 GitHub Releases, 4 Changelogs, 2 not available. |
|
Hey, sorry for the noise. This was caused by a bug in our automated dependency update system that incorrectly included upstream changelog content in PR comments, triggering notifications to external contributors. The feature flag has been turned off and we're working on a fix. Sorry about that again. |
Summary: High-severity security update — 15 packages upgraded (MINOR changes included)
Manifests changed:
.(pnpm)✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.
Updates
Packages marked with "-" are updated due to dependency constraints.
Security Details
🚨 Critical & High Severity (4 fixed)
ℹ️ Other Vulnerabilities (7)
bind:innerTextandbind:textContentbind:innerTextandbind:textContent.mapHandlingformremote function leading to Denial of Service (experimental only)Review Checklist
Standard review:
Update Mode: Vulnerability Remediation (High)
🤖 Generated by DataDog Automated Dependency Management System