Skip to content

Conversation

@tnm
Copy link
Contributor

@tnm tnm commented Jan 8, 2026

Summary

Fix the remaining 5 Dependabot alerts in npm lockfiles.

Changes

kit-mcp-site:

  • next.js 15.5.6 → 15.5.9 (critical RCE fix)
  • glob (high - command injection)
  • js-yaml (moderate - prototype pollution)

clients/typescript:

  • js-yaml (moderate - prototype pollution)

Test plan

  • npm audit returns 0 vulnerabilities in both directories

- kit-mcp-site: fix next.js RCE (critical), glob injection (high), js-yaml (moderate)
- clients/typescript: fix js-yaml prototype pollution (moderate)
@tnm tnm merged commit 44f06d7 into main Jan 8, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants