Skip to content

fix: qs past the advisory, and the owner back on the CLA allowlist - #42

Merged
rgdevment merged 2 commits into
mainfrom
fix/qs
Oct 4, 2026
Merged

rgdevment merged 2 commits into
mainfrom
fix/qs

Conversation

@rgdevment

Copy link
Copy Markdown
Owner

typed-rest-client (through Stryker) pins qs to 6.15.1, inside GHSA-q8mj-m7cp-5q26. An override lifts it to
6.16.0; npm audit is clean and Stryker still kills 31 of 41 on theme.ts. Development only.

typed-rest-client pins qs to 6.15.1,
  inside the vulnerable range, so Dependabot's security update failed. An override lifts it to 6.16.0. It is a development dependency
  and ships in nothing.
@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

All contributors have signed the CLA. Thanks!

@rgdevment rgdevment changed the title fix: qs past the advisory, under the Stryker client that pins it fix: qs past the advisory, under the Stryker client that pins it Oct 4, 2026
@rgdevment

Copy link
Copy Markdown
Owner Author

I have read the CLA Document and I hereby sign the CLA

rgdevment added a commit to rgdevment/cla-signatures that referenced this pull request Oct 4, 2026
@rgdevment rgdevment changed the title fix: qs past the advisory, under the Stryker client that pins it fix: qs past the advisory, and the owner back on the CLA allowlist Oct 4, 2026
@rgdevment
rgdevment merged commit 3a974c7 into main Oct 4, 2026
22 checks passed
@rgdevment
rgdevment deleted the fix/qs branch October 4, 2026 04:59
rgdevment added a commit that referenced this pull request Oct 4, 2026
…iew left (#43)

Slint 1.18 renamed viewport-height to content-height; the picker list
was the only use and every build warned about it. commits.sh refuses a
title or subject that runs over more than one line, which a pasted PR
title did on #42. The column-zero rule fails when grep cannot read the
workflows. One composite action installs the toolchain for every job,
and paired install-action steps become one.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant