Skip to content

Commit d4eb05f

Browse files
committed
DOC-3386: Consolidate dependency security fixes
- Upgrade http-server from ^0.12.3 to ^14.1.1 (v14 drops ecstatic) - Remove ecstatic devDependency (no longer needed) - Add liquidjs resolution (>=10.25.7) — the only transitive vulnerability not fixable via direct dependency upgrade (@tinymce/antora-extension-livedemos pins ^9.37.0) Supersedes #4028, #4093, #4094, #4102, #4120, #4121, #4122. yarn audit: 0 vulnerabilities.
1 parent fbc2650 commit d4eb05f

2 files changed

Lines changed: 312 additions & 157 deletions

File tree

package.json

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -30,16 +30,18 @@
3030
"delay": "2500ms",
3131
"ext": "*"
3232
},
33+
"resolutions": {
34+
"liquidjs": ">=10.25.7"
35+
},
3336
"devDependencies": {
3437
"@antora/cli": "^3.1.10",
3538
"@antora/site-generator-default": "^3.1.10",
3639
"@tinymce/antora-extension-livedemos": "^0.1.0",
3740
"@tinymce/moxiedoc": "^0.3.0",
3841
"dom-to-semantic-markdown": "^1.5.0",
3942
"dotenv": "^16.5.0",
40-
"ecstatic": "^4.1.4",
4143
"gpt-tokenizer": "^3.4.0",
42-
"http-server": "^0.12.3",
44+
"http-server": "^14.1.1",
4345
"jsdom": "^24.1.0",
4446
"nodemon": "^3.1.10",
4547
"npm-run-all": "^4.1.5"

0 commit comments

Comments
 (0)