Skip to content

Conversation

@MikeMcC399
Copy link
Collaborator

Situation

npm audit and Dependabot report CVE-2026-22036 (Low severity) in undici (GHSA-g9mf-h72j-4rw9)

Change

Update the following dependencies as follows:

Package Before After
@actions/cache 5.0.3 5.0.5
@actions/core 2.0.2 2.0.3

Verification

npm ci
npm run format:all:check
npm run lint
npm run check:markdown-links

Update
@actions/cache to 5.0.4
@actions/core to 2.0.3
@cypress-app-bot
Copy link

@MikeMcC399 MikeMcC399 added bug Something isn't working type: dependencies labels Jan 28, 2026
@MikeMcC399 MikeMcC399 self-assigned this Jan 28, 2026
@MikeMcC399 MikeMcC399 marked this pull request as ready for review January 28, 2026 07:24
@jennifer-shehane jennifer-shehane merged commit 0f330eb into cypress-io:master Jan 28, 2026
86 checks passed
@github-actions
Copy link

🎉 This PR is included in version 7.1.1 🎉

The release is available on:

Your semantic-release bot 📦🚀

@MikeMcC399 MikeMcC399 deleted the update/at-actions branch January 28, 2026 14:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants