Skip to content

Commit 57dd33d

Browse files
committed
chore(docs): patch dependabot vulns via npm overrides
- Override serialize-javascript to ^7.0.5 (fixes CVE GHSA-76p7-773f-r4q5 RCE and GHSA-xxx CPU exhaustion DoS in transitive deps from copy-webpack-plugin and css-minimizer-webpack-plugin) - Override postcss to ^8.5.10 (fixes XSS via unescaped </style>) - npm audit now reports 0 vulnerabilities
1 parent 41de19f commit 57dd33d

2 files changed

Lines changed: 15 additions & 21 deletions

File tree

docusaurus/package-lock.json

Lines changed: 11 additions & 21 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

docusaurus/package.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -29,6 +29,10 @@
2929
"devDependencies": {
3030
"@docusaurus/module-type-aliases": "3.9.2"
3131
},
32+
"overrides": {
33+
"serialize-javascript": "^7.0.5",
34+
"postcss": "^8.5.10"
35+
},
3236
"browserslist": {
3337
"production": [
3438
">0.5%",

0 commit comments

Comments
 (0)