Skip to content

[release/9.0] Update npm dependencies - #67143

Merged
wtgodbe merged 4 commits into
dotnet:release/9.0from
wtgodbe:infrastructure/update-npm-packages-release-9.0-2026-06-10
Jun 11, 2026
Merged

[release/9.0] Update npm dependencies#67143
wtgodbe merged 4 commits into
dotnet:release/9.0from
wtgodbe:infrastructure/update-npm-packages-release-9.0-2026-06-10

Conversation

@wtgodbe

@wtgodbe wtgodbe commented Jun 10, 2026

Copy link
Copy Markdown
Member

No description provided.

Copilot AI review requested due to automatic review settings June 10, 2026 21:04

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@wtgodbe wtgodbe added the tell-mode Indicates a PR which is being merged during tell-mode label Jun 10, 2026
Bump rollup 4.24.0 -> 4.61.1 to fix high-severity path-traversal advisory (GHSA-mw96-cpmx-2vgc).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@wtgodbe
wtgodbe force-pushed the infrastructure/update-npm-packages-release-9.0-2026-06-10 branch from c385646 to 49a2d4b Compare June 10, 2026 21:09
…es release/10.0)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@wtgodbe
wtgodbe requested a review from a team as a code owner June 10, 2026 21:40
@github-actions github-actions Bot added the area-blazor Includes: Blazor, Razor Components label Jun 10, 2026
wtgodbe and others added 2 commits June 10, 2026 15:01
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
… under TypeScript 5.9 (matches release/10.0)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@wtgodbe
wtgodbe merged commit 840866c into dotnet:release/9.0 Jun 11, 2026
24 of 26 checks passed
Comment thread package-lock.json
"version": "8.18.3",
"resolved": "https://pkgs.dev.azure.com/dnceng/public/_packaging/dotnet-public-npm/npm/registry/ws/-/ws-8.18.3.tgz",
"integrity": "sha1-tWuIq//eYnkcY5FwQAyT3LDJVHI=",
"version": "8.20.1",

@omajid omajid Jun 17, 2026

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@wtgodbe This PR updates ws to 8.21.0 further down which resolves GHSA-96hv-2xvq-fx4p but we are still using 8.20.1 here, which is still vulnerable. Is there a plan to fix this?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for catching that - #67277

This was referenced Jul 15, 2026
renebentes pushed a commit to renebentes/3054 that referenced this pull request Aug 3, 2026
Updated
[Microsoft.AspNetCore.OpenApi](https://github.com/dotnet/aspnetcore)
from 9.0.17 to 9.0.18.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.AspNetCore.OpenApi's
releases](https://github.com/dotnet/aspnetcore/releases)._

## 9.0.18

[Release](https://github.com/dotnet/core/releases/tag/v9.0.18)

## What's Changed
* Update branding to 9.0.18 by @​vseanreesermsft in
dotnet/aspnetcore#66983
* [release/9.0] (deps): Bump src/submodules/googletest from `d72f9c8` to
`a721f1b` by @​dependabot[bot] in
dotnet/aspnetcore#66974
* [release/9.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/aspnetcore#66717
* [release/9.0] Update dependencies from dotnet/extensions by
@​dotnet-maestro[bot] in dotnet/aspnetcore#66640
* [release/9.0] Update dependencies from dotnet/source-build-assets by
@​dotnet-maestro[bot] in dotnet/aspnetcore#66992
* [release/9.0] Add 1ES Unofficial pipeline for Components E2E tests by
@​wtgodbe in dotnet/aspnetcore#66988
* [release/9.0] Bump Crypto.Xml to 8.0.3 for RepoTasks by @​wtgodbe in
dotnet/aspnetcore#66765
* Merging internal commits for release/9.0 by @​vseanreesermsft in
dotnet/aspnetcore#67104
* [release/9.0] Update npm dependencies by @​wtgodbe in
dotnet/aspnetcore#67143
* [release/9.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/aspnetcore#67057
* [release/9.0] Update Microsoft Identity Web package versions to 3.15.1
by @​wtgodbe in dotnet/aspnetcore#67163
* [release/9.0] (deps): Bump src/submodules/googletest from `a721f1b` to
`7140cd4` by @​dependabot[bot] in
dotnet/aspnetcore#67217
* [release/9.0] Update dependencies from dotnet/source-build-assets by
@​dotnet-maestro[bot] in dotnet/aspnetcore#67113
* [release/9.0] Reject ASCII control characters in cookie auth return
URLs by @​github-actions[bot] in
dotnet/aspnetcore#67156


**Full Changelog**:
dotnet/aspnetcore@v9.0.17...v9.0.18

Commits viewable in [compare
view](dotnet/aspnetcore@v9.0.17...v9.0.18).
</details>

[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=Microsoft.AspNetCore.OpenApi&package-manager=nuget&previous-version=9.0.17&new-version=9.0.18)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-blazor Includes: Blazor, Razor Components tell-mode Indicates a PR which is being merged during tell-mode

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants