Commit 9224399
chore(deps): bump basic-ftp to 5.3.0 and vite to 7.3.2
Supersedes #42 (npm-security group) and #44 (vite direct bump) —
both blocked by branch-name governance. Re-created on a codex-
compliant branch per docs/SECURITY.md.
- basic-ftp: pnpm.overrides pin ^5.2.0 -> ^5.3.0 (security group)
- vite: devDependency ^7.0.4 -> ^7.3.2 (minor, plugin-react 5 safe)
#43 (picomatch 2.3.1 -> 2.3.2) intentionally skipped: picomatch@2.3.1
is a transitive dep pinned by a parent, and a minor-patch bump isn't
worth an override hack. Picomatch@4.0.3 coexists at the latest major
already.
Validated locally:
- pnpm install resolves cleanly to basic-ftp 5.3.0 and vite 7.3.2
- pnpm build: 636ms
- pnpm test: 127/127
- pnpm typecheck: clean
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>1 parent ebba089 commit 9224399
2 files changed
Lines changed: 21 additions & 21 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
112 | 112 | | |
113 | 113 | | |
114 | 114 | | |
115 | | - | |
| 115 | + | |
116 | 116 | | |
117 | 117 | | |
118 | 118 | | |
| |||
138 | 138 | | |
139 | 139 | | |
140 | 140 | | |
141 | | - | |
| 141 | + | |
142 | 142 | | |
143 | 143 | | |
144 | 144 | | |
| |||
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments