Skip to content

Commit 8cf8312

Browse files
committed
fix(website): resolve Dependabot security alerts (serialize-javascript, undici, svgo, minimatch, dompurify)
- serialize-javascript: 7.0.3 (RCE via RegExp.flags/toISOString) - undici: 7.24.1 (WebSocket/server_max_window_bits, permessage-deflate, CRLF, smuggling, DoS) - svgo: 3.3.3 (Billion Laughs DoS in DOCTYPE) - minimatch: 10.2.3 (ReDoS GLOBSTAR and extglobs) - dompurify: 3.3.3 (XSS) Added resolutions (yarn) and overrides (npm) to pin patched versions. npm audit and lockfiles regenerated; 0 vulnerabilities. Made-with: Cursor
1 parent 7d8abad commit 8cf8312

3 files changed

Lines changed: 340 additions & 404 deletions

File tree

website/package-lock.json

Lines changed: 27 additions & 45 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

website/package.json

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -62,14 +62,22 @@
6262
"schema-utils": "4.3.3",
6363
"node-forge": "1.3.3",
6464
"qs": "6.14.2",
65-
"minimatch": "10.2.1"
65+
"minimatch": "10.2.3",
66+
"serialize-javascript": "7.0.3",
67+
"undici": "7.24.1",
68+
"svgo": "3.3.3",
69+
"dompurify": "3.3.3"
6670
},
6771
"overrides": {
6872
"ajv": "8.18.0",
6973
"ajv-keywords": "5.1.0",
7074
"schema-utils": "4.3.3",
7175
"node-forge": "1.3.3",
7276
"qs": "6.14.2",
73-
"minimatch": "10.2.1"
77+
"minimatch": "10.2.3",
78+
"serialize-javascript": "7.0.3",
79+
"undici": "7.24.1",
80+
"svgo": "3.3.3",
81+
"dompurify": "3.3.3"
7482
}
7583
}

0 commit comments

Comments
 (0)