fix: Security updates #25
+24
−24
Merged
StepSecurity Actions Security / StepSecurity Required Checks
succeeded
Apr 3, 2026 in 0s
StepSecurity Required Checks
Finished StepSecurity Required Checks
- Pwn Request Vulnerabilities Check - Checks for Pwn Request vulnerabilities in the PR via risky triggers
- Script Injection Check - Checks for script injection vulnerabilities in the PR
- NPM Compromised Packages Check - Checks for compromised npm package versions in the PR
- NPM Package Cooldown Check - Fails if any package version in the PR was released within the configured cooldown period, helping to avoid brand-new (and potentially unreviewed or malicious) releases
Details
✅ Pwn Request Vulnerabilities Check
No Pwn Request vulnerabilities found in this PR.
✅ Script Injection Vulnerabilities Check
No Script Injection vulnerabilities found in this PR.
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
✅ NPM Package Cooldown Check
No npm package upgrades to recent releases found in current PR.
The following npm packages are inspected in current PR
| Package Name | Previous Version | Current Version | file | Current Version Release Date |
|---|---|---|---|---|
| lodash | 4.17.23 | 4.18.1 | package-lock.json | 2026-04-01T21:01:20Z |
| brace-expansion | 1.1.12 | 1.1.13 | package-lock.json | 2026-03-27T08:39:34Z |
| handlebars | 4.7.8 | 4.7.9 | package-lock.json | 2026-03-26T20:46:39Z |
| picomatch | 2.3.1 | 2.3.2 | package-lock.json | 2026-03-23T20:39:08Z |
⏲️ History
Previous invocation results of same check:
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
❌ NPM Package Cooldown Check
✅ Pwn Request Vulnerabilities Check
No Pwn Request vulnerabilities found in this PR.
✅ Script Injection Vulnerabilities Check
No Script Injection vulnerabilities found in this PR.
To approve check run click here
⏲️ History
Previous invocation results of same check:
✅ Pwn Request Vulnerabilities Check
No Pwn Request vulnerabilities found in this PR.
✅ Script Injection Vulnerabilities Check
No Script Injection vulnerabilities found in this PR.
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
❌ NPM Package Cooldown Check
To approve check run click here
Loading