Commit 9cd09fe
committed
Bump vulnerable transitive deps via overrides
Adds follow-redirects, ws, and brace-expansion to the overrides block to
close Dependabot alerts (header leak, uninitialized memory disclosure,
DoS) and the corresponding npm audit findings. Also widens existing vite
and qs floors. picomatch and postcss pick up patched versions via the
lockfile refresh.1 parent 0a21eda commit 9cd09fe
2 files changed
Lines changed: 168 additions & 147 deletions
0 commit comments