Skip to content

Resolve critical and high dependency alerts #3

Description

@jongan69

This is the owned security backlog for the currently open critical and high Dependabot alerts in this retained repository.

Snapshot: 2026-08-14T18:30:40.721Z
Repository: jongan69/expo-sony-camera
Critical: 0
High: 8

Disposition: actionable. Group compatible patch and minor updates on dev, validate the repository, and promote through a reviewed passing PR. Handle major or behavior-changing upgrades separately. Do not mass-merge these alerts.

Acceptance: every item below is closed by a verified upgrade or moved to a separate linked exception issue with an owner, rationale, compensating controls, and review date.

  • high brace-expansion — example/package-lock.json, runtime — alert #5
  • high brace-expansion — example/package-lock.json, runtime — alert #7
  • high image-size — example/package-lock.json, runtime — alert #11
  • high image-size — example/package-lock.json, runtime — alert #12
  • high js-yaml — example/package-lock.json, runtime — alert #10
  • high js-yaml — package-lock.json, development — alert #17
  • high js-yaml — package-lock.json, development — alert #18
  • high nanoid — example/package-lock.json, runtime — alert #13

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions