Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Update vulnerable npm dependencies

Open
#969 0 comments 1 reaction 2 assignees View on GitHub

@rzhao271 is already working on this.

Since Sep 14, 2026.

  • #970 by @copilot-swe-agent — closed without merging

Assessment

This issue has not been assessed yet.

Description

Component Governance reports this npm dependency update is available in the VS Code feed:

  • brace-expansion: 2.1.0 -> 2.1.3

Update the applicable direct or transitive dependency and validate the change with the repository's relevant tests, linting, and build. Do not use dependency overrides, resolutions, --force, --legacy-peer-deps, or equivalent force flags to resolve the vulnerability.

Dominant language
TypeScript
Stars
2k
Forks
337
Avg merge
21h 58m
Merged PRs (30d)
3

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from microsoft/node-pty

All issues in microsoft/node-pty

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.