Commit f96cd28
fix(deps): bump brace-expansion, postcss, and tar to patch HIGH severity CVEs
MegaLinter trivy scan flagged CVE-2026-14257 (brace-expansion DoS),
GHSA-r28c-9q8g-f849 (postcss path traversal), and GHSA-r292-9mhp-454m
(tar stack-overflow DoS) in transitive dependencies.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Signed-off-by: Efren Lim <elim@linuxfoundation.org>1 parent fb9023d commit f96cd28
2 files changed
Lines changed: 195 additions & 252 deletions
0 commit comments