Commit 45137eb
fix(deps): Update tar and vite to resolve security vulnerabilities (GHSA-vmf3-w455-68vh, GHSA-v6wh-96g9-6wx3, GHSA-fx2h-pf6j-xcff)
Add npm overrides for tar >=7.5.16 and vite >=8.0.16 to fix:
- tar: PAX size override file smuggling vulnerability (moderate)
- vite: NTLMv2 hash disclosure via UNC path handling (high)
- vite: server.fs.deny bypass on Windows alternate paths (high)
This resolves the Security workflow failure (run #154).
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>1 parent ee67acc commit 45137eb
2 files changed
Lines changed: 94 additions & 92 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
86 | 86 | | |
87 | 87 | | |
88 | 88 | | |
89 | | - | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
90 | 92 | | |
91 | 93 | | |
0 commit comments