Commit ceb2ea3
committed
fix(deps): resolve security vulnerabilities in transitive dependencies
Add pnpm overrides to patch vulnerable dev dependencies:
- lodash: 4.17.21 → 4.17.23 (prototype pollution in _.unset/_.omit)
- undici: 6.21.3 → 6.23.0 (unbounded decompression chain DoS)
- glob: 10.4.5 → 10.5.0 (command injection via -c/--cmd)
Also updates direct dev dependencies:
- @biomejs/biome: 2.2.5 → 2.3.8
- nano-staged: 0.8.0 → 0.9.0
- release-it: 19.0.5 → 19.1.0
Resolves GitHub Dependabot alerts #23, #24, #25.1 parent 8679c6e commit ceb2ea3
2 files changed
Lines changed: 24 additions & 12 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
114 | 114 | | |
115 | 115 | | |
116 | 116 | | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
117 | 124 | | |
118 | 125 | | |
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments