Skip to content

fix(deps): update vulnerable client dependencies - #42214

Merged
subrata71 merged 1 commit into
releasefrom
fix/dependabot-ce-batch-20260909
Sep 9, 2026
Merged

fix(deps): update vulnerable client dependencies#42214
subrata71 merged 1 commit into
releasefrom
fix/dependabot-ce-batch-20260909

Conversation

@appsmith-smithes

@appsmith-smithes appsmith-smithes Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Summary

Updates vulnerable client dependencies using direct version bumps and Yarn resolutions.

Resolved alerts

This is the CE source-of-truth counterpart to appsmith-ee PR #9706. The EE-only colord alert is not present in CE.

No code changes — dependency versions and resolutions only. Local yarn install --no-immutable and production build passed with Node 24.14.1.

/ok-to-test tags="@tag.All"

Tip

🟢 🟢 🟢 All cypress tests have passed! 🎉 🎉 🎉
Workflow run: https://github.com/appsmithorg/appsmith/actions/runs/34344959521
Commit: be4f08b
Cypress dashboard.
Tags: @tag.All
Spec:


Wed, 09 Sep 2026 12:34:45 UTC

@appsmith-smithes appsmith-smithes Bot added ok-to-test Required label for CI hacktron-exclude Skip Hacktron security scan for this PR labels Sep 9, 2026
@appsmith-smithes
appsmith-smithes Bot marked this pull request as ready for review September 9, 2026 12:49
@appsmith-smithes
appsmith-smithes Bot requested a review from a team as a code owner September 9, 2026 12:49
@appsmith-smithes
appsmith-smithes Bot requested a review from subrata71 September 9, 2026 12:49
@subrata71
subrata71 merged commit cda4e09 into release Sep 9, 2026
101 of 104 checks passed
@subrata71
subrata71 deleted the fix/dependabot-ce-batch-20260909 branch September 9, 2026 12:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hacktron-exclude Skip Hacktron security scan for this PR ok-to-test Required label for CI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant