Commit 04e20cf
authored
chore(deps): bump dev dependencies via yarn up -R '*' (#8724)
Closes form-data CVE-2026-12143 by bumping form-data 4.0.5 → 4.0.6 (both
^4.0.5 from axios and ~4.0.4 from @cypress/request collapse onto the
patched version).
Lockfile-only change. Notable transitive shifts:
- caniuse-api 3.0.0 → 4.0.0 (drops lodash.memoize / lodash.uniq) via
postcss-* family 8.0.0 → 8.0.1 patch bumps
- node-gyp 'latest' channel → 13.0.0 (used by fsevents); ^12.1.0 channel
(npmcli) stays on 12.x
- oxc-resolver 11.20.0 → 11.21.3 (storybook dep) pulls @emnapi/* and
@napi-rs/wasm-runtime as wasm-fallback transitives
- http(s)-proxy-agent 9.0.0 → 9.1.0 introduces proxy-agent-negotiate
- tcp-port-used 1.0.2 → 1.0.3 hard-pins is2@2.0.1, which in turn pulls
ip-regex ^2.1.0 — no known advisories on either; both are dev-only
Cypress test infra
- Routine patch/data bumps: caniuse-lite, electron-to-chromium, acorn,
nanoid, undici, semver, rollup, axe-core, body-parser, hono, postcss-*,
and the usual es-abstract micro-bumps
nodemailer remains on 8.0.11 (capped by monocart-coverage-reports); the
open CVE is not reachable from this repo's usage.1 parent fa3c919 commit 04e20cf
1 file changed
Lines changed: 673 additions & 545 deletions
0 commit comments