Skip to content

[Snyk] Security upgrade @c15t/react from 1.8.5 to 1.8.6#12392

Open
sestinj wants to merge 1 commit into
mainfrom
snyk-fix-93c5b600bd040725274cc45ae96c8426
Open

[Snyk] Security upgrade @c15t/react from 1.8.5 to 1.8.6#12392
sestinj wants to merge 1 commit into
mainfrom
snyk-fix-93c5b600bd040725274cc45ae96c8426

Conversation

@sestinj
Copy link
Copy Markdown
Contributor

@sestinj sestinj commented May 13, 2026

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • docs/package.json
  • docs/package-lock.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity SQL Injection
SNYK-JS-KYSELY-16642092
  833  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 SQL Injection


Summary by cubic

Upgrade @c15t/react in docs from 1.8.5 to 1.8.6 to remediate a high‑severity SQL injection in transitive kysely (SNYK-JS-KYSELY-16642092). Lockfile refreshed to pull in safe versions.

  • Dependencies
    • @c15t/react^1.8.6
    • Transitive: c15t/@c15t/backend → 1.8.6 (uses kysely ≥0.28.15), @orpc/* → 1.13.13/1.14.3, plus patch bumps (e.g., opentelemetry, protobufjs, zustand)

Written for commit 399516a. Summary will update on new commits.

@sestinj sestinj requested a review from a team as a code owner May 13, 2026 07:58
@dosubot dosubot Bot added the size:XS This PR changes 0-9 lines, ignoring generated files. label May 13, 2026
@continue
Copy link
Copy Markdown
Contributor

continue Bot commented May 13, 2026

Documentation Review

No documentation updates are needed for this PR.

Reason: This is a routine Snyk security patch that bumps @c15t/react from 1.8.5 to 1.8.6 in the docs site dependencies. This is an internal dependency upgrade with no changes to APIs, configuration, or developer-facing behavior that would require documentation updates.

Copy link
Copy Markdown
Contributor

@cubic-dev-ai cubic-dev-ai Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS This PR changes 0-9 lines, ignoring generated files.

Projects

Status: Todo

Development

Successfully merging this pull request may close these issues.

2 participants