Skip to content

fix: update nanoid to resolve CVE-2026-67213 - #28

Closed
independabot-soc2[bot] wants to merge 1 commit into
mainfrom
independabot/nanoid-CVE-2026-67213
Closed

fix: update nanoid to resolve CVE-2026-67213#28
independabot-soc2[bot] wants to merge 1 commit into
mainfrom
independabot/nanoid-CVE-2026-67213

Conversation

@independabot-soc2

Copy link
Copy Markdown
Contributor

Hi, this is independabot — not Lili! You can ask her if you have questions, but she had no hand in generating this PR other than setting up the independabot schedule.

Please merge this PR yourself, if you approve.

BEFORE YOU MERGE

Instructions for resolving the vuln — test to make sure that nothing is broken, check compatibility, etc.

Highlight the risky code / where the dependency was used

nanoid isn't a direct dependency — it's pulled in transitively by postcss (used by @tailwindcss/postcss). No app code references it directly, so no compatibility impact expected.

Special instructions for this PR

None.

AFTER YOU MERGE

None.

Co-Authored-By: Warp agent@warp.dev

Co-Authored-By: Oz <oz-agent@warp.dev>
@independabot-soc2
independabot-soc2 Bot requested a review from dannyneira August 17, 2026 13:07
@independabot-soc2

Copy link
Copy Markdown
Contributor Author

Closing as duplicate — this same nanoid 3.3.18 fix (CVE-2026-67213 / GHSA-2v37-7h3g-55p8) is already covered by #27.

@independabot-soc2
independabot-soc2 Bot deleted the independabot/nanoid-CVE-2026-67213 branch August 17, 2026 13:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant