build(deps): resolve the eight open Dependabot security alerts (#1635)

Bump astro 7.2.4 → 7.2.10 (critical, website build) and retarget the pinned
pnpm overrides for the transitive alerts: js-yaml → 4.3.2 (the one runtime
path, via electron-updater), smol-toml → 1.7.1 (new key for nx's exact 1.6.1
pin), svgo → 4.1.0 (new key for astro's 4.0.2 resolution) and hono → 4.13.5.
Every target stays inside its parent's declared range except nx's exact
smol-toml pin, which is now recorded as the deliberate exception in
docs/architecture/dependency-security-overrides.md.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
4grayandClaude Fable 5.1 authored and GitHub committed 2026-09-19 18:02:07 +02:00
1 parent 033a08cad9
commit f13d0c55da
4 files changed
+176 -149

No files matched your search

+8 -6
View File
@@ -200,7 +200,7 @@
"@typescript-eslint/parser": "^8.69.0",
"@typescript-eslint/utils": "^8.69.0",
"angular-eslint": "22.5.0",
"astro": "7.2.4",
"astro": "7.2.10",
"autoprefixer": "10.5.4",
"cookie": "2.0.1",
"cors": "2.8.6",
@@ -261,11 +261,11 @@
"follow-redirects@1.15.11": "1.16.0",
"form-data@4.0.5": "4.0.6",
"h3@1.15.5": "1.15.10",
"hono@4.12.0": "4.12.34",
"hono@4.12.0": "4.13.5",
"immutable@5.1.4": "5.1.9",
"ip-address@10.1.0": "10.5.0",
"js-yaml@4.1.1": "4.3.1",
"js-yaml@4.3.0": "4.3.1",
"js-yaml@4.1.1": "4.3.2",
"js-yaml@4.3.0": "4.3.2",
"jsdom>ws": "8.21.3",
"lodash-es@4.17.22": "4.18.1",
"minimatch@3.1.2": "3.1.5",
@@ -278,9 +278,11 @@
"qs@6.14.1": "6.15.3",
"rollup@4.52.3": "4.59.0",
"serialize-javascript@6.0.2": "7.1.0",
"smol-toml@1.6.0": "1.6.1",
"smol-toml@1.6.0": "1.7.1",
"smol-toml@1.6.1": "1.7.1",
"svgo@3.3.2": "3.3.3",
"svgo@4.0.0": "4.0.2",
"svgo@4.0.0": "4.1.0",
"svgo@4.0.2": "4.1.0",
"undici@7.28.0": "7.29.0",
"uuid@8.3.2": "11.1.1",
"yaml@1.10.2": "1.10.3"