Skip to content

Update dependency to fix vulnerabilities#10217

Merged
timotheeguerin merged 14 commits intomicrosoft:mainfrom
timotheeguerin:upgrade-deps/vuln-2026-03-31
Mar 31, 2026
Merged

Update dependency to fix vulnerabilities#10217
timotheeguerin merged 14 commits intomicrosoft:mainfrom
timotheeguerin:upgrade-deps/vuln-2026-03-31

Conversation

@timotheeguerin
Copy link
Copy Markdown
Member

@timotheeguerin timotheeguerin commented Mar 31, 2026

  • yarnpkg/core which had pinned to an old version of tar
  • remove mocha in the vscode web test as its full of outdated dependency and is really just not needed for that smoke test
  • remove unsued node-stdlib-browser also using outdated dependencies but not even used

@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Mar 31, 2026

All changed packages have been documented.

  • @typespec/bundler
  • @typespec/playground
  • typespec-vscode
Show changes

@typespec/bundler - internal ✏️

Update dependency to fix vulnerabilities

@typespec/playground - internal ✏️

Update dependency to fix vulnerabilities

typespec-vscode - internal ✏️

Update dependency to fix vulnerabilities

@microsoft-github-policy-service microsoft-github-policy-service bot added ide Issues for VS, VSCode, Monaco, etc. ui:playground labels Mar 31, 2026
@pkg-pr-new
Copy link
Copy Markdown

pkg-pr-new bot commented Mar 31, 2026

Open in StackBlitz

npm i https://pkg.pr.new/@typespec/bundler@10217
npm i https://pkg.pr.new/@typespec/playground@10217
npm i https://pkg.pr.new/typespec-vscode@10217

commit: b72b497

@azure-sdk
Copy link
Copy Markdown
Collaborator

azure-sdk commented Mar 31, 2026

You can try these changes here

🛝 Playground 🌐 Website 🛝 VSCode Extension

@timotheeguerin timotheeguerin added this pull request to the merge queue Mar 31, 2026
Merged via the queue into microsoft:main with commit af0ef02 Mar 31, 2026
42 checks passed
@timotheeguerin timotheeguerin deleted the upgrade-deps/vuln-2026-03-31 branch March 31, 2026 20:52
msyyc pushed a commit that referenced this pull request Apr 1, 2026
- yarnpkg/core which had pinned to an old version of tar
- remove mocha in the vscode web test as its full of outdated dependency
and is really just not needed for that smoke test
- remove unsued `node-stdlib-browser` also using outdated dependencies
but not even used
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ide Issues for VS, VSCode, Monaco, etc. ui:playground

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants