Commit 6a08512
fix(deps): Update overrides for brace-expansion, postcss, and tar to resolve security vulnerabilities
Bump npm overrides to fix Security workflow failure (run #182):
- brace-expansion >=5.0.8: DoS via exponential-time expansion (GHSA-3jxr-9vmj-r5cp)
and OOM crash from unbounded expansion (GHSA-mh99-v99m-4gvg)
- postcss >=8.5.18: path traversal via sourceMappingURL auto-loading (GHSA-r28c-9q8g-f849)
- tar >=7.5.21: multiple critical issues including PAX numeric path confusion (GHSA-w8wr-v893-vjvp),
decompression DoS (GHSA-23hp-3jrh-7fpw), negative size infinite loop (GHSA-8x88-c5mf-7j5w),
NUL byte exception DoS (GHSA-gvwx-54wh-qm9j), and stack-overflow DoS (GHSA-r292-9mhp-454m)
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>1 parent 45137eb commit 6a08512
2 files changed
Lines changed: 17 additions & 17 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
84 | 84 | | |
85 | 85 | | |
86 | 86 | | |
87 | | - | |
88 | | - | |
| 87 | + | |
| 88 | + | |
89 | 89 | | |
90 | | - | |
| 90 | + | |
91 | 91 | | |
92 | 92 | | |
93 | 93 | | |
0 commit comments