Skip to content

Commit 485e1e0

Browse files
Bump vulnerable transitive deps via npm audit fix
Clears all high-severity advisories (axios, protobufjs, js-cookie, qs via express/body-parser, ip-address, @protobufjs/utf8): 24 -> 15 findings, all remaining are moderate/low and gated behind breaking majors (elliptic chain under blue-js-sdk's cosmjs 0.33 pin; uuid/ws under @privy-io/js-sdk-core) - deferred rather than force-bumped. Mini Shai-Hulud supply-chain check: not affected. No @antv/@tanstack/ size-sensor/echarts/timeago/SAP packages in the lockfile; no bun_environment.js / setup_bun.js / router_init.js / tanstack_runner.js artifacts; no campaign markers or exfil domains in node_modules; all five install lifecycle scripts audited and legitimate.
1 parent 629c505 commit 485e1e0

1 file changed

Lines changed: 108 additions & 63 deletions

File tree

package-lock.json

Lines changed: 108 additions & 63 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)