Commit 57dd33d
committed
chore(docs): patch dependabot vulns via npm overrides
- Override serialize-javascript to ^7.0.5 (fixes CVE GHSA-76p7-773f-r4q5
RCE and GHSA-xxx CPU exhaustion DoS in transitive deps from
copy-webpack-plugin and css-minimizer-webpack-plugin)
- Override postcss to ^8.5.10 (fixes XSS via unescaped </style>)
- npm audit now reports 0 vulnerabilities1 parent 41de19f commit 57dd33d
2 files changed
Lines changed: 15 additions & 21 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
29 | 29 | | |
30 | 30 | | |
31 | 31 | | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
32 | 36 | | |
33 | 37 | | |
34 | 38 | | |
| |||
0 commit comments