Skip to content

chore(deps): broaden http-proxy-middleware override to cover full advisory range [security]#34082

Merged
EugeniyKiyashko merged 1 commit into
DevExpress:26_1from
EugeniyKiyashko:26_1_middlewhare
Jun 19, 2026
Merged

chore(deps): broaden http-proxy-middleware override to cover full advisory range [security]#34082
EugeniyKiyashko merged 1 commit into
DevExpress:26_1from
EugeniyKiyashko:26_1_middlewhare

Conversation

@EugeniyKiyashko

Copy link
Copy Markdown
Contributor

No description provided.

@EugeniyKiyashko EugeniyKiyashko self-assigned this Jun 19, 2026
Copilot AI review requested due to automatic review settings June 19, 2026 12:57

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Broadens the pnpm override for http-proxy-middleware to ensure vulnerable versions across the full advisory range are resolved to a safe version, keeping the monorepo’s dependency tree aligned with security requirements.

Changes:

  • Expanded the http-proxy-middleware override selector range from >=3.0.4 <3.0.7 to >=0.16.0 <3.0.7.
  • Updated pnpm-lock.yaml to reflect the override effect (notably eliminating http-proxy-middleware@2.0.9 in favor of 3.0.7).

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.

File Description
pnpm-workspace.yaml Broadens the overrides selector range for http-proxy-middleware to cover older vulnerable versions.
pnpm-lock.yaml Regenerated lockfile reflecting the new override, resolving http-proxy-middleware to 3.0.7 where applicable.
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

@EugeniyKiyashko EugeniyKiyashko merged commit 66e1317 into DevExpress:26_1 Jun 19, 2026
130 of 131 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants