fix(deps): bump ip-address, brace-expansion and postcss for open CVEs (stable) (#988)
Backport of #987. stable carried the same vulnerable versions. brace-expansion 5.0.8 -> 5.0.9 CVE-2026-69152 (high) ip-address 10.2.0 -> 10.4.0 CVE-2026-69192 (high), CVE-2026-54272, CVE-2026-69198 (medium) — SSRF and trust-boundary bypasses postcss 8.5.18 -> 8.5.23 CVE-2026-69153 (medium) Lockfile holds exactly one entry per package, all at or above the fixed version; the image installs via npm ci --omit=dev.
This commit is contained in:
@@ -55,7 +55,7 @@
|
||||
"pdf-lib": "^1.17.1",
|
||||
"pdfkit": "^0.17.2",
|
||||
"pg": "^8.16.3",
|
||||
"postcss": "8.5.18",
|
||||
"postcss": "8.5.23",
|
||||
"qrcode": "^1.5.4",
|
||||
"react-i18next": "^15.6.0",
|
||||
"sanitize-html": "2.17.5",
|
||||
@@ -85,13 +85,13 @@
|
||||
"fast-xml-parser": ">=5.7.0",
|
||||
"qs": ">=6.15.2",
|
||||
"tar": ">=7.5.21",
|
||||
"brace-expansion": ">=5.0.7",
|
||||
"brace-expansion": ">=5.0.9",
|
||||
"minimatch": ">=9.0.7",
|
||||
"path-to-regexp": "0.1.13",
|
||||
"lodash": ">=4.18.1",
|
||||
"follow-redirects": ">=1.16.0",
|
||||
"@tootallnate/once": ">=3.0.1",
|
||||
"ip-address": ">=10.1.1",
|
||||
"ip-address": ">=10.3.1",
|
||||
"uuid": "^11.1.1",
|
||||
"nodemailer": "^9.0.1"
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user