0fe5792a7d
Backport of #987. stable carried the same vulnerable versions. brace-expansion 5.0.8 -> 5.0.9 CVE-2026-69152 (high) ip-address 10.2.0 -> 10.4.0 CVE-2026-69192 (high), CVE-2026-54272, CVE-2026-69198 (medium) — SSRF and trust-boundary bypasses postcss 8.5.18 -> 8.5.23 CVE-2026-69153 (medium) Lockfile holds exactly one entry per package, all at or above the fixed version; the image installs via npm ci --omit=dev.