Skip to content

fix: regenerate pnpm lockfile to resolve axios CVE alerts - #6

Open
betterbrand wants to merge 1 commit into
mainfrom
fix/axios-lockfile
Open

fix: regenerate pnpm lockfile to resolve axios CVE alerts#6
betterbrand wants to merge 1 commit into
mainfrom
fix/axios-lockfile

Conversation

@betterbrand

Copy link
Copy Markdown

Adds a CI workflow that regenerates pnpm-lock.yaml with axios 1.16.0+ to clear HIGH-severity Dependabot alerts.

Addresses lockfile-sourced alerts — axios is a transitive dependency so the fix is a lockfile regeneration rather than a direct dep bump.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant