Skip to content

fix: update nitropack to resolve CVE-2026-44372 and CVE-2026-44373#82

Draft
dannyneira wants to merge 1 commit into
mainfrom
independabot/nitropack-CVE-2026-44372-CVE-2026-44373
Draft

fix: update nitropack to resolve CVE-2026-44372 and CVE-2026-44373#82
dannyneira wants to merge 1 commit into
mainfrom
independabot/nitropack-CVE-2026-44372-CVE-2026-44373

Conversation

@dannyneira
Copy link
Copy Markdown
Member

Summary

  • Updated transitive npm dependency nitropack from 2.13.3 to 2.13.4 in package-lock.json.
  • Resolves the grouped Dependabot alerts for CVE-2026-44372 and CVE-2026-44373.
  • No direct dependency or override was added; this is a lockfile-only transitive update.

Security alerts

Advisories

Verification

  • npm audit no longer reports nitropack.
  • npm run build passed.
  • npm run typecheck passed with 0 errors and existing hints only.
  • npm run lint could not run in this sandbox because trunk is not installed.

Conversation: https://staging.warp.dev/conversation/afca70f9-a90b-442c-80fd-2d073799a893
Run: https://oz.staging.warp.dev/runs/019e3184-3c43-7402-ad9b-0a6cc3a2ba17
This PR was generated with Oz.

@dannyneira dannyneira requested a review from rachaelrenk May 16, 2026 16:09
@cla-bot cla-bot Bot added the cla-signed label May 16, 2026
@vercel
Copy link
Copy Markdown

vercel Bot commented May 16, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
docs Ready Ready Preview, Comment May 16, 2026 4:11pm

Request Review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant