Commit 9cdab34
committed
fix(security): resolve high dependency alerts
- Patch JavaScript audit overrides for high advisory transitive dependencies.
- Update openssl and hickory resolver dependencies and adapt DNS resolver API usage.
- Replace deterministic crypto test keys with generated keys to avoid hard-coded cryptographic values.
Tests: npx --yes pnpm@9.15.9 ui:gate:static; npx --yes pnpm@9.15.9 test; npx --yes pnpm@9.15.9 test:security-regression; npx --yes pnpm@9.15.9 audit --audit-level high; npx --yes pnpm@9.15.9 git:guard:all; cd src-tauri && cargo check1 parent 936daca commit 9cdab34
6 files changed
Lines changed: 265 additions & 155 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
139 | 139 | | |
140 | 140 | | |
141 | 141 | | |
142 | | - | |
143 | | - | |
| 142 | + | |
| 143 | + | |
144 | 144 | | |
145 | 145 | | |
| 146 | + | |
| 147 | + | |
146 | 148 | | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
147 | 153 | | |
| 154 | + | |
148 | 155 | | |
149 | 156 | | |
150 | 157 | | |
| |||
0 commit comments