fix
patch
deps
feat/phase-2g-bundle
#59 / 100
fix(deps): patch high/critical CVEs in hub/bridge and hub/gateway (npm audit fix)
Clears the CI "Audit dependencies — fail on high/critical CVEs" gate.
- hub/bridge: bumps transitive tmp to >=0.2.6 (GHSA-ph9p-34f9-6g65, HIGH path traversal) under @netlify/blobs -> @netlify/dev-utils -> tmp-promise; also patches qs DoS (GHSA-q8mj-m7cp-5q26) and uuid bounds check. - hub/gateway: patches the same qs/body-parser/express moderate chain.
Lockfile-only (no package.json range changes); npm audit --audit-level=high --omit=dev now reports 0 vulnerabilities in root, hub/gateway, and hub/bridge. Full test suite unaffected (no auth/gateway/blob regressions).
sha256:c61f9731834905266919f40c189595a1e43ef7bb72a63fb4bb7d785cb68f46e7
sha
sha256:bc87c2f8f62995507560975210a3ad3b89c2f668d5aa200288cbefcaa9ff946a
snapshot
Older
Merge remote-tracking branch 'origin/main' into feat/persistent-login
sha256:2c4a5dbc881ade389a734f7738f4144492fe7fef0cc54a5b99918b0251f565e6
All commits
Newer
fix(test): scope note-outline route-source extraction to the not…
sha256:dd4c9835ab6c546d287b63f7ae138b54e9bc32295ab15b030aeb558ae759d802
0 comments
To add a comment, use the Muse CLI:
muse hub commit comment sha256:c61f9731834905266919f40c189595a1e43ef7bb72a63fb4bb7d785cb68f46e7 --body "your comment"
No comments yet. Be the first to start the discussion.