5
0
mirror of https://gitea.com/actions/setup-python.git synced 2026-08-05 02:31:29 +00:00

fix: resolve npm audit high severity vulnerabilities (#1347)

- Upgrade fast-xml-parser to 5.10.1 (fixes GHSA-8r6m-32jq-jx6q)
- Add package.json override to force brace-expansion >=5.0.8 across
  all transitive dependencies (fixes GHSA-mh99-v99m-4gvg) without
  downgrading jest/ts-jest
- Refresh .licenses/npm cache to match updated dependency tree
- Rebuild dist/setup and dist/cache-save

npm audit now reports 0 vulnerabilities. Pre-existing test suite
failures (7 suites, ESM/jest teardown issue) verified unrelated to
this change - identical on unmodified main with node 24.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
Haritha
2026-08-03 11:18:19 -05:00
committed by GitHub
parent 5fda3b95a4
commit 8549b9f8f5
15 changed files with 2247 additions and 1490 deletions
+2 -2
View File
@@ -1,10 +1,10 @@
---
name: is-unsafe
version: 1.0.1
version: 2.0.0
type: npm
summary: Zero-dependency, DOM-free, pure predicate for detecting unsafe strings across
HTML, XML, SVG, SQL, SHELL, and REGEX contexts
homepage:
homepage:
license: mit
licenses:
- sources: LICENSE