fix: override yauzl to 3.2.1 to resolve moderate vulnerability
Some checks failed
Build & Deploy to Staging / Build & Deploy to Staging (push) Has been cancelled
Some checks failed
Build & Deploy to Staging / Build & Deploy to Staging (push) Has been cancelled
yauzl <3.2.1 has an off-by-one error (GHSA-gmq8-994r-jv83). Transitive dependency via puppeteer → @puppeteer/browsers → extract-zip. npm overrides pins yauzl@3.2.1 without changing puppeteer version. npm audit now reports 0 vulnerabilities.
This commit is contained in:
parent
8f70a32f77
commit
14181d17a7
2 changed files with 11 additions and 14 deletions
|
|
@ -41,5 +41,8 @@
|
|||
"typescript": "^5.9.3",
|
||||
"vitest": "^4.1.0"
|
||||
},
|
||||
"type": "module"
|
||||
"type": "module",
|
||||
"overrides": {
|
||||
"yauzl": "3.2.1"
|
||||
}
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue