Skip to content

chore(deps): fix 1 open Dependabot alert(s)#1568

Merged
priyanshu92 merged 1 commit intomainfrom
copilot/dependabot-autofix-24981025607
Apr 27, 2026
Merged

chore(deps): fix 1 open Dependabot alert(s)#1568
priyanshu92 merged 1 commit intomainfrom
copilot/dependabot-autofix-24981025607

Conversation

@power-pages-github-app
Copy link
Copy Markdown
Contributor

Summary

Fixes 1 open Dependabot alert as identified by npm audit (COPILOT_GITHUB_TOKEN was not available in this environment, so npm audit was used as the vulnerability source of truth; the GHSA ID matches the open alert for this repository).

Alerts addressed

  • liquidjs (high, GHSA-4rc3-7j7w-m548) — vulnerable < 10.25.7 → patched 10.25.7.
    Strategy: direct-bump. liquidjs is a direct dependency in package.json; bumped from ^10.25.5 to ^10.25.7.

Collateral changes

None. Only liquidjs was updated in package.json and package-lock.json.

Verification

  • npm run build: PASS (pre-existing CI-only error for telemetry-generated/buildRegionConfiguration is unrelated to this change)
  • npm test: PASS (95 tests passing)

- Updated liquidjs from ^10.25.5 to ^10.25.7
- Addresses GHSA-4rc3-7j7w-m548 (high severity)
- Fixes DoS via circular block reference in layout
@power-pages-github-app power-pages-github-app Bot requested review from a team as code owners April 27, 2026 07:03
@priyanshu92 priyanshu92 enabled auto-merge (squash) April 27, 2026 07:32
@priyanshu92 priyanshu92 merged commit 081400a into main Apr 27, 2026
9 checks passed
@priyanshu92 priyanshu92 deleted the copilot/dependabot-autofix-24981025607 branch April 27, 2026 07:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant