Skip to content

fix(deps): update dependencies to solve high vulnerabilities#1242

Closed
TakahashiNguyen wants to merge 23 commits intonest-modules:mainfrom
524H0003:main
Closed

fix(deps): update dependencies to solve high vulnerabilities#1242
TakahashiNguyen wants to merge 23 commits intonest-modules:mainfrom
524H0003:main

Conversation

@TakahashiNguyen
Copy link
Copy Markdown

This PR hopefully fixes an issue where install the package gives project 32 high vulnerabilities.

@TakahashiNguyen TakahashiNguyen changed the title fix: update dependencies to solve high vulnerabilities fix(deps): update dependencies to solve high vulnerabilities Jan 28, 2025
@ricono-tyler
Copy link
Copy Markdown

Any chance this will actually get reviewed and merged in?

@frantisekff
Copy link
Copy Markdown

Hello @AnhNg6262 , thanks for your PR. Do you know if this PR will be merged soon? Thanks

@cmoreira-handtevy
Copy link
Copy Markdown

Any update on this PR?

@jetie000
Copy link
Copy Markdown

@juandav Can you please have a look at this huge securiry problem

@Destroy666x
Copy link
Copy Markdown

Looks like the project is basically dead. @juandav is active on GH but 0 replies in this repo, it looks like. It's very unprofessional to abandon stuff completely like this, without even merging in security vulnerability fixes. At least pass it to someone interested, please.

@rlcDev
Copy link
Copy Markdown

rlcDev commented Jun 11, 2025

The module keeps having +200k downloads a week and new vulnerabilities are spotted.
Please take the security concerns seriously

@stoberov
Copy link
Copy Markdown

@juandav - thank you for your library and the efforts so far! But any chance to at least reply if this will ever actually be considered to get merged? Or we should start looking for an alternative library / fork this one?

@Nirator78
Copy link
Copy Markdown

@juandav any date for merge of this pr please ?

@titouan-joseph
Copy link
Copy Markdown

Hello @eduardoleal @cdiaz @juandav @kitimark

Please have a look at this PR
There are several vulnerabilities on the dependencies !

Thank you

@Nirator78
Copy link
Copy Markdown

Yes please, accept the pr :)

juandav added a commit that referenced this pull request Mar 21, 2026
- fix(service): use logger.log instead of debug for transporter ready message (#1239, #1248, #1249)
- fix(service): reuse createTransporter in addTransporter for consistent verification and hooks (#1234)
- fix(liquid): initialize config with default empty object to prevent TypeError (#1232)
- fix(mjml): add optional chaining for others param to prevent crash when undefined
- fix(deps): add peerDependenciesMeta to mark template engines as optional (#1238, #1244)
- fix(deps): move tslib from devDependencies to dependencies for PnP runtime support (#1230)
- chore(deps): update devDependencies to latest compatible versions (#1242, #1250)
- docs: add Liquid adapter examples, MJML clarifications, multi-transporter docs (#1246)
- docs: add pnpm installation instructions and liquidjs to README

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
juandav added a commit that referenced this pull request Mar 21, 2026
- fix(service): use logger.log instead of debug for transporter ready message (#1239, #1248, #1249)
- fix(service): reuse createTransporter in addTransporter for consistent verification and hooks (#1234)
- fix(liquid): initialize config with default empty object to prevent TypeError (#1232)
- fix(mjml): add optional chaining for others param to prevent crash when undefined
- fix(deps): add peerDependenciesMeta to mark template engines as optional (#1238, #1244)
- fix(deps): move tslib from devDependencies to dependencies for PnP runtime support (#1230)
- chore(deps): update devDependencies to latest compatible versions (#1242, #1250)
- docs: add Liquid adapter examples, MJML clarifications, multi-transporter docs (#1246)
- docs: add pnpm installation instructions and liquidjs to README

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
@juandav
Copy link
Copy Markdown
Member

juandav commented Mar 21, 2026

Superseded by branch fix/multiple-issues-and-dependency-updates which includes comprehensive dependency updates along with bug fixes and documentation improvements.

@juandav
Copy link
Copy Markdown
Member

juandav commented Mar 21, 2026

Closing as superseded — all dependency updates are included in the comprehensive fix branch.

@juandav juandav closed this Mar 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.