iemejia opened a new pull request, #3753:
URL: https://github.com/apache/avro/pull/3753

   ## Summary
   
   - Remove deprecated `coveralls` dependency (source of unfixable 
vulnerabilities via `request`)
   - Add npm `overrides` to force safe versions of transitive dependencies: 
`diff` 8.0.4, `serialize-javascript` 7.0.5, `lodash` 4.18.1, `minimatch` 3.1.5, 
`uuid` 14.0.0
   - Resolves all 18 npm audit vulnerabilities to 0
   
   ## Testing
   
   All 383 tests pass on Node.js 20, 22, and 24.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to