Skip to content

fix(deps): resolve Dependabot alerts - #57

Open
narcisonunez wants to merge 2 commits into
mainfrom
fix/dependabot-alerts
Open

narcisonunez wants to merge 2 commits into
mainfrom
fix/dependabot-alerts

Conversation

@narcisonunez

@narcisonunez narcisonunez commented Sep 29, 2026 •

Copy link
Copy Markdown

Summary

Resolves all 38 open Dependabot alerts. pnpm audit now reports no known vulnerabilities.

Package Before After Type
axios 1.15.0 1.20.0 runtime (direct)
form-data 4.0.5 4.0.6 runtime (via axios)
vitest / @vitest/mocker 4.1.4 4.1.11 dev
vite 8.0.8 8.3.1 dev (peer of vitest)
postcss 8.5.10 8.5.28 dev (via vite)
nanoid 3.3.11 3.3.19 dev (via postcss)
esbuild 0.27.7 0.28.2 dev (via vite/tsx)
  • vite is now listed as an explicit devDependency. It was only installed as an auto-installed peer of vitest, and pnpm update doesn't bump those.
  • std-env stays at 4.2.0. CI runs pnpm 11, whose default minimumReleaseAge rejects 4.3.0, which was published today.

Validation

  • pnpm build and pnpm test pass.
  • pnpm audit reports no known vulnerabilities.
  • Ran the built CLI against a local mock Dokploy API. The outgoing HTTP requests (paths, x-api-key header, GET input params, POST { json } bodies), the output, error handling and auth behave the same before and after the bump.
  • The lockfile installs with --frozen-lockfile on both pnpm 10 and pnpm 11.

@narcisonunez narcisonunez changed the title fix(deps): resolve Dependabot alerts + add e2e tests fix(deps): resolve Dependabot alerts Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant