fix: Security updates #4
+246
−450
Merged
StepSecurity Actions Security / StepSecurity Required Checks
succeeded
Jan 16, 2026 in 5s
StepSecurity Required Checks
Finished StepSecurity Required Checks
- Script Injection Check - Checks for script injection vulnerabilities in the PR
- NPM Compromised Packages Check - Checks for compromised npm package versions in the PR
- NPM Package Cooldown Check - Fails if any package version in the PR was released within the configured cooldown period, helping to avoid brand-new (and potentially unreviewed or malicious) releases
- Pwn Request Vulnerabilities Check - Checks for Pwn Request vulnerabilities in the PR via risky triggers
Details
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
✅ Pwn Request Vulnerabilities Check
No Pwn Request vulnerabilities found in this PR.
✅ Script Injection Vulnerabilities Check
No Script Injection vulnerabilities found in this PR.
✅ NPM Package Cooldown Check
No npm package upgrades to recent releases found in current PR.
The following npm packages are inspected in current PR
| Package Name | Previous Version | Current Version | file | Current Version Release Date |
|---|---|---|---|---|
| @babel/helpers | 7.16.7 | 7.28.6 | package-lock.json | 2026-01-12T17:50:02Z |
| @babel/traverse | 7.16.7 | 7.28.6 | package-lock.json | 2026-01-12T17:50:02Z |
| @babel/template | 7.16.7 | 7.28.6 | package-lock.json | 2026-01-12T17:50:00Z |
| @babel/generator | 7.16.7 | 7.28.6 | package-lock.json | 2026-01-12T17:50:00Z |
| @babel/parser | 7.22.16 | 7.28.6 | package-lock.json | 2026-01-12T17:49:42Z |
| @babel/types | 7.22.19 | 7.28.6 | package-lock.json | 2026-01-12T17:49:39Z |
| @babel/code-frame | 7.18.6 | 7.28.6 | package-lock.json | 2026-01-12T17:49:33Z |
| js-yaml | 4.1.0 | 4.1.1 | package-lock.json | 2025-11-12T15:18:03Z |
| @babel/helper-validator-identifier | 7.22.20 | 7.28.5 | package-lock.json | 2025-10-23T15:17:38Z |
| @jridgewell/trace-mapping | 0.3.19 | 0.3.31 | package-lock.json | 2025-09-10T20:12:49Z |
| @jridgewell/sourcemap-codec | 1.4.15 | 1.5.5 | package-lock.json | 2025-08-12T06:43:59Z |
| @jridgewell/gen-mapping | 0.3.13 | package-lock.json | 2025-08-12T06:43:21Z | |
| @babel/helper-globals | 7.28.0 | package-lock.json | 2025-07-02T08:38:14Z | |
| brace-expansion | 1.1.11 | 1.1.12 | package-lock.json | 2025-06-11T08:52:58Z |
| @babel/helper-string-parser | 7.22.5 | 7.27.1 | package-lock.json | 2025-04-30T15:08:26Z |
| jsesc | 2.5.2 | 3.1.0 | package-lock.json | 2024-12-11T08:24:34Z |
| cross-spawn | 7.0.3 | 7.0.6 | package-lock.json | 2024-11-18T13:59:52Z |
| picocolors | 1.0.0 | 1.1.1 | package-lock.json | 2024-10-16T18:20:03Z |
| micromatch | 4.0.4 | 4.0.8 | package-lock.json | 2024-08-23T16:31:18Z |
| braces | 3.0.2 | 3.0.3 | package-lock.json | 2024-05-21T08:59:11Z |
| fill-range | 7.0.1 | 7.1.1 | package-lock.json | 2024-05-21T08:45:51Z |
| semver | 6.3.0 | 6.3.1 | package-lock.json | 2023-07-10T22:38:41Z |
⏲️ History
Previous invocation results of same check:
✅ Pwn Request Vulnerabilities Check
No Pwn Request vulnerabilities found in this PR.
✅ Script Injection Vulnerabilities Check
No Script Injection vulnerabilities found in this PR.
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
✅ NPM Package Cooldown Check
No npm package upgrades to recent releases found in current PR.
The following npm packages are inspected in current PR
| Package Name | Previous Version | Current Version | file | Current Version Release Date |
|---|---|---|---|---|
| @babel/helpers | 7.16.7 | 7.28.6 | package-lock.json | 2026-01-12T17:50:02Z |
| @babel/traverse | 7.16.7 | 7.28.6 | package-lock.json | 2026-01-12T17:50:02Z |
| @babel/template | 7.16.7 | 7.28.6 | package-lock.json | 2026-01-12T17:50:00Z |
| @babel/generator | 7.16.7 | 7.28.6 | package-lock.json | 2026-01-12T17:50:00Z |
| @babel/parser | 7.22.16 | 7.28.6 | package-lock.json | 2026-01-12T17:49:42Z |
| @babel/types | 7.22.19 | 7.28.6 | package-lock.json | 2026-01-12T17:49:39Z |
| @babel/code-frame | 7.18.6 | 7.28.6 | package-lock.json | 2026-01-12T17:49:33Z |
| js-yaml | 4.1.0 | 4.1.1 | package-lock.json | 2025-11-12T15:18:03Z |
| @babel/helper-validator-identifier | 7.22.20 | 7.28.5 | package-lock.json | 2025-10-23T15:17:38Z |
| @jridgewell/trace-mapping | 0.3.19 | 0.3.31 | package-lock.json | 2025-09-10T20:12:49Z |
| @jridgewell/sourcemap-codec | 1.4.15 | 1.5.5 | package-lock.json | 2025-08-12T06:43:59Z |
| @jridgewell/gen-mapping | 0.3.13 | package-lock.json | 2025-08-12T06:43:21Z | |
| @babel/helper-globals | 7.28.0 | package-lock.json | 2025-07-02T08:38:14Z | |
| brace-expansion | 1.1.11 | 1.1.12 | package-lock.json | 2025-06-11T08:52:58Z |
| @babel/helper-string-parser | 7.22.5 | 7.27.1 | package-lock.json | 2025-04-30T15:08:26Z |
| jsesc | 2.5.2 | 3.1.0 | package-lock.json | 2024-12-11T08:24:34Z |
| cross-spawn | 7.0.3 | 7.0.6 | package-lock.json | 2024-11-18T13:59:52Z |
| picocolors | 1.0.0 | 1.1.1 | package-lock.json | 2024-10-16T18:20:03Z |
| micromatch | 4.0.4 | 4.0.8 | package-lock.json | 2024-08-23T16:31:18Z |
| braces | 3.0.2 | 3.0.3 | package-lock.json | 2024-05-21T08:59:11Z |
| fill-range | 7.0.1 | 7.1.1 | package-lock.json | 2024-05-21T08:45:51Z |
| semver | 6.3.0 | 6.3.1 | package-lock.json | 2023-07-10T22:38:41Z |
⏲️ History
Previous invocation results of same check:
Loading