fix(security): resolve all npm audit vulnerabilities
Frontend (6 → 0 vulnerabilities): - axios: update to fix DoS via __proto__ key in mergeConfig (CVE-2026-25639) - swiper: update to fix prototype pollution (critical) - rollup: update to fix arbitrary file write via path traversal - minimatch: update to fix multiple ReDoS vulnerabilities - ajv: update to fix ReDoS with $data option - markdown-it: update to fix ReDoS Backend (32 → 0 vulnerabilities): - multer: update to fix DoS via incomplete cleanup and resource exhaustion - minimatch: update to fix multiple ReDoS vulnerabilities - Add npm overrides for transitive dependencies: - fast-xml-parser >=5.3.8 (fixes XSS, DoS, stack overflow via AWS SDK) - qs >=6.14.2 (fixes arrayLimit bypass DoS via Express) - tar >=7.5.8 (fixes path traversal and hardlink attacks via sqlite3) Docker: - Pin nginx base image to 1.27-alpine in Dockerfile.prod - Update security comments in backend Dockerfile - Existing apk upgrade --no-cache ensures OpenSSL/libexpat CVEs are patched at build time (OpenSSL 3.5.5, Alpine 3.23.3)
This commit is contained in:
Generated
+785
-811
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user