Commit 485e1e0
committed
Bump vulnerable transitive deps via npm audit fix
Clears all high-severity advisories (axios, protobufjs, js-cookie, qs via
express/body-parser, ip-address, @protobufjs/utf8): 24 -> 15 findings, all
remaining are moderate/low and gated behind breaking majors (elliptic chain
under blue-js-sdk's cosmjs 0.33 pin; uuid/ws under @privy-io/js-sdk-core) -
deferred rather than force-bumped.
Mini Shai-Hulud supply-chain check: not affected. No @antv/@tanstack/
size-sensor/echarts/timeago/SAP packages in the lockfile; no
bun_environment.js / setup_bun.js / router_init.js / tanstack_runner.js
artifacts; no campaign markers or exfil domains in node_modules; all five
install lifecycle scripts audited and legitimate.1 parent 629c505 commit 485e1e0
1 file changed
Lines changed: 108 additions & 63 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments