[GH-ISSUE #431] Security Alert: 12 npm vulnerabilities found #270

Closed
opened 2026-05-06 12:27:45 +02:00 by BreizhHardware · 1 comment

Originally created by @github-actions[bot] on GitHub (Feb 18, 2026).
Original GitHub issue: https://github.com/maziggy/bambuddy/issues/431

Originally assigned to: @maziggy on GitHub.

Automated Security Audit Results

The weekly security audit found vulnerabilities in npm dependencies.

Package Severity Via Fix
@eslint-community/eslint-utils moderate eslint Yes
@eslint/eslintrc moderate ajv Yes
@typescript-eslint/eslint-plugin moderate @typescript-eslint/parser, @typescript-eslint/type-utils, @typescript-eslint/utils, eslint Yes
@typescript-eslint/parser moderate eslint Yes
@typescript-eslint/type-utils moderate @typescript-eslint/utils, eslint Yes
@typescript-eslint/utils moderate @eslint-community/eslint-utils, eslint Yes
ajv moderate ajv Yes
eslint moderate @eslint-community/eslint-utils, @eslint/eslintrc, ajv Yes
eslint-plugin-react-refresh moderate eslint No
npm high tar No
tar high tar No
typescript-eslint moderate @typescript-eslint/eslint-plugin, @typescript-eslint/parser, @typescript-eslint/utils, eslint Yes
  1. Review each vulnerability: npm audit
  2. Auto-fix if possible: npm audit fix
  3. Manual fix for breaking changes: npm audit fix --force (review changes!)
  4. Close this issue when resolved

This issue was automatically created by the security audit workflow.

Originally created by @github-actions[bot] on GitHub (Feb 18, 2026). Original GitHub issue: https://github.com/maziggy/bambuddy/issues/431 Originally assigned to: @maziggy on GitHub. ## Automated Security Audit Results The weekly security audit found vulnerabilities in npm dependencies. | Package | Severity | Via | Fix | |---------|----------|-----|-----| | @eslint-community/eslint-utils | moderate | eslint | Yes | | @eslint/eslintrc | moderate | ajv | Yes | | @typescript-eslint/eslint-plugin | moderate | @typescript-eslint/parser, @typescript-eslint/type-utils, @typescript-eslint/utils, eslint | Yes | | @typescript-eslint/parser | moderate | eslint | Yes | | @typescript-eslint/type-utils | moderate | @typescript-eslint/utils, eslint | Yes | | @typescript-eslint/utils | moderate | @eslint-community/eslint-utils, eslint | Yes | | ajv | moderate | ajv | Yes | | eslint | moderate | @eslint-community/eslint-utils, @eslint/eslintrc, ajv | Yes | | eslint-plugin-react-refresh | moderate | eslint | No | | npm | high | tar | No | | tar | high | tar | No | | typescript-eslint | moderate | @typescript-eslint/eslint-plugin, @typescript-eslint/parser, @typescript-eslint/utils, eslint | Yes | ### Recommended Actions 1. Review each vulnerability: `npm audit` 2. Auto-fix if possible: `npm audit fix` 3. Manual fix for breaking changes: `npm audit fix --force` (review changes!) 4. Close this issue when resolved --- *This issue was automatically created by the security audit workflow.*
Author
Owner

@maziggy commented on GitHub (Feb 18, 2026):

289dc2d5d6

<!-- gh-comment-id:3920563168 --> @maziggy commented on GitHub (Feb 18, 2026): 289dc2d5d6c65011eed49b5a279cec1eec2a42c8
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/bambuddy#270
No description provided.