Skip to content

Conversation

@zwhitfield3
Copy link
Contributor

Description

This PR fixes the high vulnerabilities associated with this repo using the results from running npm audit fix. These vulnerability fixes required updating the jsonwebtoken dependency from v8.5.1 to v9.0.2. However, none of the breaking changes from upgrading to the new major version affected the repo source code.

Testing

N/A

Screenshots (if applicable)

Screenshot 2025-07-29 at 11 57 09 AM

SOC2 Compliance

Gus Work Item: W-19111805 (Heroku internal)

@zwhitfield3 zwhitfield3 requested a review from a team as a code owner July 29, 2025 19:40
Copy link

@sbosio sbosio left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@zwhitfield3 zwhitfield3 merged commit 9c17409 into main Jul 29, 2025
@zwhitfield3 zwhitfield3 deleted the zw/fix-dependency-vulns branch July 29, 2025 19:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants