Files
iptvnator/.changes/deps-security-2026-09.md
T
4grayandClaude Fable 5.1 f13d0c55da build(deps): resolve the eight open Dependabot security alerts (#1635)
Bump astro 7.2.4 → 7.2.10 (critical, website build) and retarget the pinned
pnpm overrides for the transitive alerts: js-yaml → 4.3.2 (the one runtime
path, via electron-updater), smol-toml → 1.7.1 (new key for nx's exact 1.6.1
pin), svgo → 4.1.0 (new key for astro's 4.0.2 resolution) and hono → 4.13.5.
Every target stays inside its parent's declared range except nx's exact
smol-toml pin, which is now recorded as the deliberate exception in
docs/architecture/dependency-security-overrides.md.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-19 18:02:07 +02:00

317 B

type, area
type area
internal deps

Closes the eight open Dependabot alerts of September 2026: astro 7.2.4 → 7.2.10 (website build), and pinned pnpm overrides moving js-yaml to 4.3.2 (the one runtime path, via electron-updater), smol-toml to 1.7.1, svgo to 4.1.0 and hono to 4.13.5. No application behavior changes.