Skip to content

Commit 22ac815

Browse files
fix: resolve Dependabot security alerts (vite, picomatch, path-to-regexp)
- vite: 7.3.1 -> 7.3.2 (fixes arbitrary file read via WebSocket, server.fs.deny bypass, path traversal in optimized deps) - picomatch: updated in both frontend and frontend-server (fixes ReDoS via extglob quantifiers, method injection in POSIX character classes) - path-to-regexp: updated in frontend-server (fixes ReDoS via multiple route parameters) - brace-expansion: updated in frontend (fixes DoS via zero-step sequence) Resolves Dependabot alerts #177, #179, #180, #181, #183, #185, #186, #187
1 parent 9fb8bc0 commit 22ac815

2 files changed

Lines changed: 33 additions & 33 deletions

File tree

src/app/frontend-server/package-lock.json

Lines changed: 6 additions & 6 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

src/app/frontend/package-lock.json

Lines changed: 27 additions & 27 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)