fix: Security updates #216
Merged
StepSecurity Actions Security / StepSecurity Required Checks
succeeded
Mar 9, 2026 in 4s
StepSecurity Required Checks
Finished StepSecurity Required Checks
- Script Injection Check - Checks for script injection vulnerabilities in the PR
- NPM Compromised Packages Check - Checks for compromised npm package versions in the PR
- NPM Package Cooldown Check - Fails if any package version in the PR was released within the configured cooldown period, helping to avoid brand-new (and potentially unreviewed or malicious) releases
- Pwn Request Vulnerabilities Check - Checks for Pwn Request vulnerabilities in the PR via risky triggers
Details
✅ Script Injection Vulnerabilities Check
No Script Injection vulnerabilities found in this PR.
✅ Pwn Request Vulnerabilities Check
No Pwn Request vulnerabilities found in this PR.
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
✅ NPM Package Cooldown Check
No npm package upgrades to recent releases found in current PR.
The following npm packages are inspected in current PR
| Package Name | Previous Version | Current Version | file | Current Version Release Date |
|---|---|---|---|---|
| tar | 7.5.6 | 7.5.10 | yarn.lock | 2026-03-04T19:42:04Z |
| strnum | 2.1.2 | 2.2.0 | yarn.lock | 2026-02-28T08:24:13Z |
| axios | 1.12.2 | 1.13.6 | yarn.lock | 2026-02-27T15:35:51Z |
| minimatch | 9.0.5 | 9.0.9 | yarn.lock | 2026-02-26T19:32:47Z |
| fast-xml-builder | 1.0.0 | yarn.lock | 2026-02-25T09:02:48Z | |
| ajv | 6.12.6 | 6.14.0 | yarn.lock | 2026-02-20T18:09:33Z |
| follow-redirects | 1.15.6 | 1.15.11 | yarn.lock | 2025-07-31T12:54:55Z |
⏲️ History
Previous invocation results of same check:
✅ Pwn Request Vulnerabilities Check
No Pwn Request vulnerabilities found in this PR.
✅ Script Injection Vulnerabilities Check
No Script Injection vulnerabilities found in this PR.
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
✅ NPM Package Cooldown Check
No npm package upgrades to recent releases found in current PR.
The following npm packages are inspected in current PR
| Package Name | Previous Version | Current Version | file | Current Version Release Date |
|---|---|---|---|---|
| tar | 7.5.6 | 7.5.10 | yarn.lock | 2026-03-04T19:42:04Z |
| strnum | 2.1.2 | 2.2.0 | yarn.lock | 2026-02-28T08:24:13Z |
| axios | 1.12.2 | 1.13.6 | yarn.lock | 2026-02-27T15:35:51Z |
| minimatch | 9.0.5 | 9.0.9 | yarn.lock | 2026-02-26T19:32:47Z |
| fast-xml-builder | 1.0.0 | yarn.lock | 2026-02-25T09:02:48Z | |
| ajv | 6.12.6 | 6.14.0 | yarn.lock | 2026-02-20T18:09:33Z |
| follow-redirects | 1.15.6 | 1.15.11 | yarn.lock | 2025-07-31T12:54:55Z |
⏲️ History
Previous invocation results of same check:
Loading