Skip to content

run npm audit fix#9

Merged
stevendborrelli merged 1 commit intocrossplane:mainfrom
stevendborrelli:update-rollup
Feb 26, 2026
Merged

run npm audit fix#9
stevendborrelli merged 1 commit intocrossplane:mainfrom
stevendborrelli:update-rollup

Conversation

@stevendborrelli
Copy link
Member

@stevendborrelli stevendborrelli commented Feb 26, 2026

Description of your changes

Update imported packages to address rollup vulnerability.

rollup  4.0.0 - 4.58.0
Severity: high
Rollup 4 has Arbitrary File Write via Path Traversal - https://github.com/advisories/GHSA-mw96-cpmx-2vgc

Fixes #

I have:

Signed-off-by: Steven Borrelli <steve@borrelli.org>
@stevendborrelli stevendborrelli merged commit f6de83f into crossplane:main Feb 26, 2026
7 checks passed
@stevendborrelli stevendborrelli deleted the update-rollup branch February 26, 2026 17:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant