[Deps] Safe dependency updates (2026-08-26)

Dependency Security Monitor · issue · closed

Filter2mode:review mode:live
All recorded Export JSON
github-actions[bot]

published Aug 26, 2026, 6:07 AM · updated Aug 26, 2026, 11:45 PM

Automated Safe Dependency Updates

This PR contains safe patch-level dependency updates that have been verified to pass tests and have no breaking changes.

Updated Dependencies

Package Previous Updated Type
js-yaml 5.2.3 5.4.0 patch
@typescript-eslint/eslint-plugin 8.66.0 8.68.0 patch
@typescript-eslint/parser 8.66.0 8.68.0 patch
typescript-eslint 8.66.0 8.68.0 patch

Security Fixes Included

No CVEs were addressed — npm audit reported 0 vulnerabilities and Dependabot alerts were inaccessible to this workflow's token (403). These are routine patch-level freshness updates.

Verification

  • npm audit — 0 vulnerabilities
  • Full test suite run: 5179/5198 tests passed. The 19 failing tests (in src/enclave/mount-policy.test.ts and 2 other suites) fail identically on main before this change, due to a missing /var/tmp directory in this sandbox environment — unrelated to the dependency bumps (confirmed via git stash comparison).
  • No breaking changes documented for any of the updated packages

Notes

Larger updates available (e.g. commander 12→15, execa 5→10, chalk 4→6, typescript 5→7, @babel/core 7→8) were intentionally skipped as they are major version bumps requiring manual review for breaking changes.


Generated by Dependency Security Monitor Workflow


Warning

Protected Files

This was originally intended as a pull request, but the patch modifies protected files. These files may affect project dependencies, CI/CD pipelines, or agent behaviour. Please review the changes carefully before creating the pull request.

Click here to create the pull request once you have reviewed the changes

Protected files
  • package-lock.json
  • package.json

To route changes like this to a review issue instead of blocking, configure protected-files: fallback-to-issue in your workflow configuration.

Warning

Firewall blocked 2 domains

The following domains were blocked by the firewall during workflow execution:

  • msfeed2.pkgs.visualstudio.com
  • msfeed25.pkgs.visualstudio.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "msfeed2.pkgs.visualstudio.com"
    - "msfeed25.pkgs.visualstudio.com"

See Network Configuration for more information.

Generated by Dependency Security Monitor · copilot · auto · 34.9 AIC · ⊞ 13.2K ·