Skip to content

Master dev - Dependabot security fixes + Contact Group SMS fix - #409

Merged
OSPFNeighbour merged 3 commits into
masterfrom
master-dev
Aug 11, 2026
Merged

Master dev - Dependabot security fixes + Contact Group SMS fix#409
OSPFNeighbour merged 3 commits into
masterfrom
master-dev

Conversation

@OSPFNeighbour

Copy link
Copy Markdown
Collaborator

OSPFNeighbour and others added 3 commits August 11, 2026 09:57
…407)

- Migrate xmldom -> @xmldom/xmldom (maintained fork; upstream xmldom
  has no fix for the critical multi-root-DOM and XML injection/DoS
  advisories). Used to parse a third-party KML feed in background.js.
- npm audit fix for js-yaml, minimatch, micromatch, nanoid, yaml
  (dev/transitive, no breaking changes).
- Pin d3-color and uuid to patched versions via npm overrides, since
  their parents (dc, exceljs) are already on latest stable and won't
  bump past the vulnerable range. Neither codepath here hits the
  vulnerable behaviour (fixed internal color values; uuidv4() called
  with no buf arg).

npm audit now reports 0 vulnerabilities.
…ield (#408)

A Contact Group (ContactTypeId 0) has no Detail/phone number of its
own — Beacon resolves its membership server-side and echoes the
result back as a separate ContactGroups field on the sent message,
rather than including the group in Recipients[]. Sending group
selections through Recipients[i] as before meant group messages
carried a null Recipient value instead of actually reaching anyone.

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.3.0 to 4.3.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.3.0...4.3.1)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.3.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@OSPFNeighbour
OSPFNeighbour merged commit 1827651 into master Aug 11, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant