Skip to content

Commit 3deb41d

Browse files
committed
security: remediate open Dependabot alerts (npm lockfile)
Bump transitive npm dependencies to patched versions via `npm audit fix` (no --force). Only package-lock.json changes; package.json manifest untouched. Advisories fixed: - nanoid 3.3.15 -> 3.3.18 (GHSA-28wg-ghj8-5hjv, GHSA-2v37-7h3g-55p8; high) - js-yaml 4.3.0 -> 4.3.1 (GHSA-5p4m-2wfm-xmqj; high) - brace-expansion -> 1.1.18 / 5.0.9 (GHSA-rgw5-rvv9-x895; high) - postcss 8.5.x -> 8.5.26 (GHSA-r28c-9q8g-f849, GHSA-fxqj-rqcc-2cmp; high/med) - sharp -> 0.35.3 (GHSA-f88m-g3jw-g9cj libvips CVEs; high) npm audit: 6 high -> 0 vulnerabilities. Python requirements.txt has no open alerts; left unchanged.
1 parent f6c7b6e commit 3deb41d

1 file changed

Lines changed: 275 additions & 187 deletions

File tree

0 commit comments

Comments
 (0)