Skip to content

fix(deps): remediate high/moderate audit advisories without breaking changes - #99

Merged
EmeditWeb merged 1 commit into
mainfrom
fix/web-deps-security-safe
Sep 16, 2026
Merged

EmeditWeb merged 1 commit into
mainfrom
fix/web-deps-security-safe

Conversation

@EmeditWeb

Copy link
Copy Markdown
Member

No description provided.

…changes

Non-forced `npm audit fix` (strict npm ci resolution, matching CI). Clears 13 high, all 11 moderate, and 1 low transitive advisories via same-major bumps (react-router, postcss, undici, nanoid, svgo, qs, @opentelemetry/*, @vitest/mocker, tar, …).

No semver-major changes: the residual 17 are the netlify-cli v27 cluster (a devDependency — build/deploy tooling, not shipped) and @stellar/stellar-sdk v15->v17 (runtime), both deferred to dedicated migration PRs.

Audit: 42 -> 17 (high 26->13, moderate 11->0, low 5->4). Verified: npm run build (tsc -b && vite build), npm run lint, npm test (vitest 10 files / 49 tests) all pass. Only package-lock.json changed.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@EmeditWeb
EmeditWeb merged commit 98f67fd into main Sep 16, 2026
2 checks passed
@EmeditWeb
EmeditWeb deleted the fix/web-deps-security-safe branch September 29, 2026 10:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant