Skip to content

Fix dependabot security issues, update vulnerable npm packages - #244

Merged
doomspork merged 3 commits into
elixirschool:mainfrom
brain-geek:dependabot-fix
Oct 29, 2025
Merged

Fix dependabot security issues, update vulnerable npm packages#244
doomspork merged 3 commits into
elixirschool:mainfrom
brain-geek:dependabot-fix

Conversation

@brain-geek

Copy link
Copy Markdown
Contributor

Right now, dependabot keeps showing security alerts for the project. Same for npm install.

This PR should fix those.

@brain-geek
brain-geek requested a review from a team as a code owner October 28, 2025 20:48
@doomspork

Copy link
Copy Markdown
Member

Hey @brain-geek!! How the heck are you? Long time no see 😁 Hope you are well.

Thanks for this! I'm trying to sort out some automation for this in my spare time to make handling the Elixir School and BEAM Community org dependabot PRs a breeze.

@doomspork
doomspork added this pull request to the merge queue Oct 29, 2025
Merged via the queue into elixirschool:main with commit d37c4f6 Oct 29, 2025
5 checks passed
@brain-geek
brain-geek deleted the dependabot-fix branch October 29, 2025 14:17
doomspork pushed a commit that referenced this pull request Apr 7, 2026
* Add nodejs version to .tool-versons

* Run `npm audit fix` to update packages with security issues

* Add missing definition for phoenix npm packages

It is needed to properly update package-lock.json which is now showing 1 vulnerable package.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants