Skip to content

Vulns march 2026#166

Draft
bgdnatx wants to merge 1 commit intomasterfrom
bogdan/vulns-202603
Draft

Vulns march 2026#166
bgdnatx wants to merge 1 commit intomasterfrom
bogdan/vulns-202603

Conversation

@bgdnatx
Copy link

@bgdnatx bgdnatx commented Mar 9, 2026

Key Dependency Updates

  • AWS SDK: Upgraded from version 2.991.0 to 2.1693.0. A deprecation notice has been added highlighting that AWS SDK v2 has reached end-of-support and users should migrate to v3.
  • Babel Ecosystem: Significant version bumps across the @babel suite (including generator, parser, traverse, and types) to version 7.28.5.
  • Mapbox Internal Tools:
    • @mapbox/dyno updated to 1.6.3.
    • @mapbox/dynamodb-test updated to 0.6.2.
  • Security & Utilities: Updates to cross-spawn (v7.0.6), nanoid (v3.3.11), postcss (v8.5.6), and lodash (v4.17.23).
  • LevelDB Ecosystem: Multiple packages (e.g., abstract-leveldown, encoding-down, levelup) are now marked as deprecated, noting they have been superseded by abstract-level packages.

Engine Requirements

  • The required Node.js engine for @mapbox/dyno has been increased from >= 10 to >= 16.
  • The aws-sdk engine requirement was raised to >= 10.0.0.

Metadata Improvements

  • The PR adds explicit "license" fields (e.g., MIT, ISC, Apache-2.0) to hundreds of package entries within the lockfile that previously lacked this metadata.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant