fix(deps): resolve dependabot alert for yauzl#68
fix(deps): resolve dependabot alert for yauzl#68KelechiOdom10 wants to merge 1 commit intomasterfrom
Conversation
Update yauzl from 3.2.0 to 3.2.1 to fix medium severity off-by-one error (CVE-2026-31988).
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
📝 Coding Plan
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment Tip You can disable poems in the walkthrough.Disable the |
Summary
yauzlfrom 3.2.0 to 3.2.1 to fix medium severity off-by-one error (CVE-2026-31988)@xhmikosr/decompress-unzippackage-lock.jsonchanged — no code changesTest plan
npm ls yauzlconfirms version 3.2.1