microsoft / microsoft/vscode-pull-request-github

Update vulnerable npm dependencies

Open
#8,956 0 comments 1 reaction 2 assignees View on GitHub

@rzhao271 is already working on this.

Since Sep 14, 2026.

  • #8957 by @copilot-swe-agent — open
Dominant language
TypeScript
Stars
2.6k
Forks
796
Avg merge
1d 4h
Merged PRs (30d)
46

Description

Component Governance reports these npm dependency updates are available in the VS Code feed:

  • brace-expansion: 1.1.13 -> 1.1.17
  • brace-expansion: 2.0.3 -> 2.1.3
  • diff: 7.0.0 -> 8.0.3
  • fast-uri: 3.1.5 -> 3.1.6
  • nanoid: 3.3.16 -> 3.3.18

Update the applicable dependency paths, account for breaking changes from the major diff upgrade, and validate with relevant tests, linting, and build. Do not use dependency overrides, resolutions, --force, --legacy-peer-deps, or equivalent force flags.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.