Commit 12697c9
Shannon Anahata
fix(deps): resolve Dependabot security alerts
Bump direct dependencies:
- dompurify: 3.3.2 -> 3.4.0 (8 medium alerts: #291-#298)
- js-cookie: ^3.0.5 -> ^3.0.7 (1 high alert: #325)
Update pnpm overrides for transitive dependencies:
- dompurify: 3.3.2 -> 3.4.0 (force transitive consumers to patched version)
- fast-xml-parser: ^5.5.7 -> ^5.7.0 (1 high: #303, 1 medium: #300)
- postcss: add ^8.5.10 override (1 medium: #301, next.js bundles 8.4.31)
- uuid: add ^11.1.1 override (1 medium: #324, no 9.x/8.x patch exists)
Lockfile updates via pnpm update:
- vite: 7.3.1 -> 7.3.5 (2 high: #287-#288, 1 medium: #289)
- picomatch: 2.3.1 -> 2.3.2, 4.0.3 -> 4.0.4 (2 high: #279-#280, 2 medium: #281-#282)
- brace-expansion: 2.0.2 -> 2.1.1 (1 medium: #284)
- yaml: 1.10.2 -> 1.10.3, 2.8.2 -> 2.9.0 (2 medium: #277-#278)
Cleanup:
- Remove @types/dompurify from devDependencies and overrides
(dompurify 3.x ships its own types; @types/dompurify is deprecated)1 parent f3287ce commit 12697c9
2 files changed
Lines changed: 147 additions & 167 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
67 | 67 | | |
68 | 68 | | |
69 | 69 | | |
70 | | - | |
| 70 | + | |
71 | 71 | | |
72 | 72 | | |
73 | 73 | | |
| |||
78 | 78 | | |
79 | 79 | | |
80 | 80 | | |
81 | | - | |
| 81 | + | |
82 | 82 | | |
83 | 83 | | |
84 | 84 | | |
| |||
136 | 136 | | |
137 | 137 | | |
138 | 138 | | |
139 | | - | |
140 | 139 | | |
141 | 140 | | |
142 | 141 | | |
| |||
171 | 170 | | |
172 | 171 | | |
173 | 172 | | |
174 | | - | |
175 | | - | |
| 173 | + | |
176 | 174 | | |
177 | 175 | | |
178 | 176 | | |
179 | 177 | | |
180 | | - | |
| 178 | + | |
181 | 179 | | |
182 | | - | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
183 | 183 | | |
184 | 184 | | |
185 | 185 | | |
| |||
0 commit comments