fix(deps): update npm to ^10.9.3 #972
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Situation
@semantic-release/npm
reported a low severity vulnerabilitynpm audit fix
continues to reports that the vulnerability cannot be fixed and refers to GHSA-v6h2-p8h4-qcjw (CVE-2025-5889 - brace-expansion Regular Expression Denial of Service vulnerability)@semantic-release/npm
reports no vulnerabilitysemantic-release
and / or@semantic-release/npm
also works around the issueChange
Update
npm
in package.json dependencies from^10.5.0
to^10.9.3
[email protected] includes the fixed dependency [email protected]
Note
packageManager
field in package.json to[email protected]
not thedependencies
field