Skip to content

deps: remediate tunnel server vulnerabilities - #977

Merged
Liangying.Wei (vicancy) merged 2 commits into
mainfrom
vicancy/fix-awps-server-dependencies
Aug 17, 2026
Merged

deps: remediate tunnel server vulnerabilities#977
Liangying.Wei (vicancy) merged 2 commits into
mainfrom
vicancy/fix-awps-server-dependencies

Conversation

@vicancy

Copy link
Copy Markdown
Member

Summary

  • upgrade vulnerable direct parents in the standalone tunnel server lockfile
  • pin patched transitive versions for Babel, flatted, tar-fs, and ws
  • remove all vulnerable versions associated with the server lockfile's 18 current Dependabot alerts

Validation

  • Yarn frozen-lockfile install
  • tunnel server TypeScript build
  • tunnel server and client lint
  • tunnel client production build

The existing Jest command finds no matching tests and exits with code 1 after the build and lint steps complete.

Upgrade the tunnel server dependency graph to patched versions while keeping its standalone lockfile isolated from the root workspace batch.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 6897cee9-248f-47db-a739-ab3a51b94527
@vicancy
Liangying.Wei (vicancy) enabled auto-merge (squash) August 17, 2026 01:50
@vicancy
Liangying.Wei (vicancy) merged commit 9374768 into main Aug 17, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants