Commit 3deb41d
committed
security: remediate open Dependabot alerts (npm lockfile)
Bump transitive npm dependencies to patched versions via `npm audit fix`
(no --force). Only package-lock.json changes; package.json manifest untouched.
Advisories fixed:
- nanoid 3.3.15 -> 3.3.18 (GHSA-28wg-ghj8-5hjv, GHSA-2v37-7h3g-55p8; high)
- js-yaml 4.3.0 -> 4.3.1 (GHSA-5p4m-2wfm-xmqj; high)
- brace-expansion -> 1.1.18 / 5.0.9 (GHSA-rgw5-rvv9-x895; high)
- postcss 8.5.x -> 8.5.26 (GHSA-r28c-9q8g-f849, GHSA-fxqj-rqcc-2cmp; high/med)
- sharp -> 0.35.3 (GHSA-f88m-g3jw-g9cj libvips CVEs; high)
npm audit: 6 high -> 0 vulnerabilities.
Python requirements.txt has no open alerts; left unchanged.1 parent f6c7b6e commit 3deb41d
1 file changed
Lines changed: 275 additions & 187 deletions
0 commit comments