chore(web): clear the 2026-07-22 JS advisory wave — overrides + lock re-resolve
bun-audit went red mid-day on a fresh advisory wave (13 findings across two snapshots of a moving DB): node-tar DoS trio+1 (critical), sharp/libvips CVEs, fast-uri host confusion, undici ×7, brace-expansion/linkify-it/js-yaml/postcss DoS-class, immutable, dompurify. All transitive pins in the management-console tree; none ship in the streaming stack. Every fix version is in-range for its consumers, so: pin overrides for the single-major packages (tar/dompurify/linkify-it/sharp/fast-uri/immutable/ undici/postcss/js-yaml — bun ignores range-scoped override keys, so plain keys) and a full lockfile re-resolve, which also lifts brace-expansion 2.1.1→2.1.2 in place while its 5.x line (minimatch@10) stays untouched. : No vulnerabilities found. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
+424
-412
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user