Commit 8a6bea7
Bump transitive deps postcss, fast-xml-parser, uuid to patched versions (#752)
Addresses Dependabot alerts:
- #68 fast-xml-parser < 5.7.0 (XML Comment/CDATA injection) -> 5.7.1
- #71 uuid < 14.0.0 (missing buffer bounds check) -> 14.0.0
- #72 postcss < 8.5.10 (XSS via unescaped </style>) -> 8.5.10
Updated pnpm overrides in src/frontend/package.json to force patched
versions of these transitive dependencies and regenerated pnpm-lock.yaml.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>1 parent 4376a9d commit 8a6bea7
2 files changed
Lines changed: 39 additions & 39 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
112 | 112 | | |
113 | 113 | | |
114 | 114 | | |
115 | | - | |
| 115 | + | |
116 | 116 | | |
117 | 117 | | |
118 | 118 | | |
119 | 119 | | |
120 | 120 | | |
121 | 121 | | |
| 122 | + | |
122 | 123 | | |
123 | 124 | | |
124 | | - | |
| 125 | + | |
| 126 | + | |
125 | 127 | | |
126 | 128 | | |
127 | 129 | | |
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments