Skip to content

[Cycode] Fix for vulnerable manifest file dependency - wait-on updated to version 8.0.5#87

Open
cycode-security[bot] wants to merge 1 commit into
mainfrom
cycode-fix-suggestion-manifest-dependency-update-27785d21-4519-4108-92b0-4cde5f76e40a
Open

[Cycode] Fix for vulnerable manifest file dependency - wait-on updated to version 8.0.5#87
cycode-security[bot] wants to merge 1 commit into
mainfrom
cycode-fix-suggestion-manifest-dependency-update-27785d21-4519-4108-92b0-4cde5f76e40a

Conversation

@cycode-security

@cycode-security cycode-security Bot commented Jun 12, 2026

Copy link
Copy Markdown

Cycode Vulnerable Dependencies Update

This pull request updates the following manifest file:

File Path Number of packages to update
ui/package.json 1

📂 ui/package.json

1 package will be updated to resolve vulnerabilities:

Package Name Current Version Updated Version
wait-on 7.2.0 8.0.5

Important

This pull request updates the major version for one or more packages. Make sure changes are tested before merging.

Warning

Lock file generation failed for one or more manifest files in this pull request. Please regenerate the lock file manually before merging.


Note

Low Risk
Single devDependency version bump with no application code changes; main risk is major-version CLI/API behavior in scripts that use wait-on, plus lockfile drift until regenerated.

Overview
Bumps the root UI monorepo devDependency wait-on from ^7.0.1 to ^8.0.5 in ui/package.json to address a reported vulnerable dependency (Cycode).

This is a major-version upgrade only; ui/package-lock.json is not updated in the diff, so installs may still resolve wait-on 7.x until npm install is run and the lockfile is committed.

Reviewed by Cursor Bugbot for commit fa787b9. Bugbot is set up for automated code reviews on this repo. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants