Security - Fix npm audit vulnerabilities #45
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
@qdrant/js-client-rest,@workos-inc/node,diff,vitest,wrangler,@cloudflare/vitest-pool-workersglob,esbuild,lodash,diff,fast-xml-parser,vite,qsglob@13.0.1,minimatch@10.1.2,@isaacs/brace-expansion@5.0.1tominimumReleaseAgeExcludeto fix the high-severity GHSA-7h2j-956f-4vf2Audit results
Before: 19 vulnerabilities reported by GitHub (5 high, 7 moderate, 7 low)
After: 3 low-severity findings remaining, all from storybook's
webpackandelliptic— unfixable until storybook updates its dependenciesNote
The
fast-xml-parseroverride can be removed once@aws-sdk/client-s3@>=3.982.0passes the 4-dayminimumReleaseAgethreshold (the fix shipped in@aws-sdk/xml-builder@3.972.4).