fix vulnerable dependencies#68
Merged
Merged
Conversation
Bumps and [picomatch](https://github.com/micromatch/picomatch). These dependencies needed to be updated together. Updates `picomatch` from 4.0.3 to 4.0.4 - [Release notes](https://github.com/micromatch/picomatch/releases) - [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md) - [Commits](micromatch/picomatch@4.0.3...4.0.4) Updates `picomatch` from 2.3.1 to 2.3.2 - [Release notes](https://github.com/micromatch/picomatch/releases) - [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md) - [Commits](micromatch/picomatch@4.0.3...4.0.4) --- updated-dependencies: - dependency-name: picomatch dependency-version: 4.0.4 dependency-type: indirect - dependency-name: picomatch dependency-version: 2.3.2 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
- `npm audit fix`
* Auto-delete workspace package-lock.json files * Stopped fake deleting top-level package-lock.json which is really important
- `npm audit fix` - update `@sillsdev/scripture`
- delete template lock files
1d11985 fix vulnerable dependencies (#152) 4b04512 Dark Mode Selector (#151) b1fa559 Add dark mode selector to match paranext-core 7bffda9 Added repoRoot (propagated changes from multi-template) (#143) a672cfb fix vulnerable dependencies (#142) dff5be1 Bump serialize-javascript from 7.0.4 to 7.0.5 (#141) 6ab81b7 Bump picomatch (#140) git-subtree-dir: src/create-process-test git-subtree-split: 1d119851050f1d687bd4d1c6e6038ac19fda8bba
1d11985 fix vulnerable dependencies (#152) 4b04512 Dark Mode Selector (#151) b1fa559 Add dark mode selector to match paranext-core 7bffda9 Added repoRoot (propagated changes from multi-template) (#143) a672cfb fix vulnerable dependencies (#142) dff5be1 Bump serialize-javascript from 7.0.4 to 7.0.5 (#141) 6ab81b7 Bump picomatch (#140) git-subtree-dir: src/theme-selector git-subtree-split: 1d119851050f1d687bd4d1c6e6038ac19fda8bba
1d11985 fix vulnerable dependencies (#152) 4b04512 Dark Mode Selector (#151) b1fa559 Add dark mode selector to match paranext-core 7bffda9 Added repoRoot (propagated changes from multi-template) (#143) a672cfb fix vulnerable dependencies (#142) dff5be1 Bump serialize-javascript from 7.0.4 to 7.0.5 (#141) 6ab81b7 Bump picomatch (#140) git-subtree-dir: src/verse-ref-view git-subtree-split: 1d119851050f1d687bd4d1c6e6038ac19fda8bba
1d11985 fix vulnerable dependencies (#152) 4b04512 Dark Mode Selector (#151) b1fa559 Add dark mode selector to match paranext-core 7bffda9 Added repoRoot (propagated changes from multi-template) (#143) a672cfb fix vulnerable dependencies (#142) dff5be1 Bump serialize-javascript from 7.0.4 to 7.0.5 (#141) 6ab81b7 Bump picomatch (#140) git-subtree-dir: src/website-viewer git-subtree-split: 1d119851050f1d687bd4d1c6e6038ac19fda8bba
- `npm audit fix`
irahopkinson
requested review from
Sebastian-ubs and
tjcouch-sil
as code owners
April 23, 2026 01:22
irahopkinson
enabled auto-merge
April 23, 2026 01:24
tombogle
approved these changes
Apr 24, 2026
tombogle
left a comment
Contributor
There was a problem hiding this comment.
I skimmed through this quickly since it seems to be equivalent to the review I did on the SF one. (It suffers from the same unfortunate dependabot wording problem, but since that isn't fixable,
@tombogle reviewed 21 files and all commit messages, and made 1 comment.
Reviewable status:complete! all files reviewed, all discussions resolved (waiting on Sebastian-ubs and tjcouch-sil).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
npm audit fixThis change is