Skip to content

Commit 615e7d7

Browse files
butler54claude
andcommitted
fix: update semantic-release dependencies to address security vulnerabilities
Bump semantic-release from v24 to v25 and @semantic-release/github from v11 to v12. Resolves 13 of 18 npm audit vulnerabilities including brace-expansion ReDoS, js-yaml prototype pollution, lodash prototype pollution, and multiple tar path traversal issues. Remaining 5 high-severity findings are in npm bundled inside @semantic-release/npm (transitive dep) and require an upstream fix. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
1 parent aa836f4 commit 615e7d7

2 files changed

Lines changed: 1985 additions & 2258 deletions

File tree

0 commit comments

Comments
 (0)