Skip to content

fix: update dependencies to resolve 6 CVEs#48

Merged
nocoo merged 1 commit into
mainfrom
fix/cve-deps
May 19, 2026
Merged

fix: update dependencies to resolve 6 CVEs#48
nocoo merged 1 commit into
mainfrom
fix/cve-deps

Conversation

@nocoo
Copy link
Copy Markdown
Owner

@nocoo nocoo commented May 19, 2026

Update direct and transitive dependencies to fix security vulnerabilities:

  • postcss >=8.5.10 (override for transitive copies)
  • undici >=7.24.0 (override, HIGH)
  • ws >=8.20.1 (override)
  • picomatch 4.0.4 (direct, HIGH)
  • vite 7.3.2 (direct, HIGH)
  • brace-expansion 5.0.6 (direct)

Also updates all other deps to latest compatible versions and fixes recharts Tooltip formatter type for recharts 3.8.x.

Closes #47

Update direct and transitive dependencies to fix security vulnerabilities:
- postcss >=8.5.10 (override for transitive copies)
- undici >=7.24.0 (override, HIGH)
- ws >=8.20.1 (override)
- picomatch 4.0.4 (direct, HIGH)
- vite 7.3.2 (direct, HIGH)
- brace-expansion 5.0.6 (direct)

Also updates all other deps to latest compatible versions.
Fix recharts Tooltip formatter type for recharts 3.8.x.

Closes #47
@nocoo nocoo merged commit 721eb61 into main May 19, 2026
7 checks passed
@nocoo nocoo deleted the fix/cve-deps branch May 19, 2026 10:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[🥝 choko] fix(security): bump deps (CVE)

1 participant