Skip to content

Security: update vulnerable dependencies (25_2)#33160

Draft
aleksei-semikozov wants to merge 16 commits intoDevExpress:25_2from
aleksei-semikozov:security/update-overrides-25_2
Draft

Security: update vulnerable dependencies (25_2)#33160
aleksei-semikozov wants to merge 16 commits intoDevExpress:25_2from
aleksei-semikozov:security/update-overrides-25_2

Conversation

@aleksei-semikozov
Copy link
Copy Markdown
Contributor

@aleksei-semikozov aleksei-semikozov commented Apr 3, 2026

No description provided.

- Align pnpm.overrides with 26_1 branch for cherry-pick compatibility
- Add overrides for: minimatch, picomatch, path-to-regexp, serialize-javascript,
  flatted, undici, socket.io-parser, lodash, lodash.template, bn.js,
  brace-expansion, cookie, diff, dompurify, eslint/plugin-kit, micromatch,
  nanoid, on-headers, ajv, yaml, tmp, tootallnate/once, tough-cookie,
  webpack, js-yaml, http-proxy-middleware, jspdf, immutable, and others
- Update node-forge override from 1.3.2 to 1.4.0
- Update tar override to cover <=7.5.9
- Update rollup override to cover >=4.0.0 <4.59.0
- Update qs override to >=6.14.2
- Bump Angular catalog from ~19.2.18 to ~19.2.20 (security patch)
- Bump Angular in demos from ~21.0.7 to ~21.2.4 (security patch)
- Bump storybook from 10.1.x to 10.2.10 (security fix)
- Reduces pnpm audit from 151 to 8 vulnerabilities
- Remaining 8 are unfixable (no patched version) or risky overrides
@aleksei-semikozov aleksei-semikozov force-pushed the security/update-overrides-25_2 branch from a89e49e to b6d0c3b Compare April 12, 2026 09:10
@aleksei-semikozov aleksei-semikozov force-pushed the security/update-overrides-25_2 branch from d761cd5 to 28fb846 Compare April 12, 2026 17:41
@aleksei-semikozov aleksei-semikozov force-pushed the security/update-overrides-25_2 branch 2 times, most recently from 30687eb to d50d7eb Compare April 12, 2026 18:58
@github-actions github-actions bot added the .d.ts label Apr 12, 2026
@aleksei-semikozov aleksei-semikozov force-pushed the security/update-overrides-25_2 branch 2 times, most recently from 6a222c5 to 389c703 Compare April 12, 2026 21:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant