mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-08 17:06:15 -08:00
Four open Dependabot alerts, all on transitive npm dependencies, so no direct dependency changes: - browserslist 4.28.1 -> 4.28.8 (GHSA-73wf-gq98-2v4g, high) - @xmldom/xmldom 0.8.13 -> 0.8.15 (GHSA-6gmq-8vp8-gcm6) - @humanfs/node 0.16.7 -> 0.16.8 (GHSA-p498-v437-472g) - postcss-selector-parser 6.1.2 -> 6.1.4 (GHSA-w9m9-85wc-3x92) @xmldom/xmldom already had an override, but its pinned target 0.8.13 had itself fallen into the widened advisory range (<= 0.8.14), so that entry is bumped rather than added. browserslist is pinned to 4.28.8 rather than the advisory's 4.28.7 because 4.28.8 was already resolved elsewhere in the tree; collapsing onto it takes browserslist from three copies to one and drops the duplicate caniuse-lite/electron-to-chromium/update-browserslist-db trees with it, so the lockfile is a net reduction. postcss-selector-parser 6.0.10 is left alone: it sits below the advisory's >= 6.1.0 lower bound. Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
402 B
402 B
type, area
| type | area |
|---|---|
| internal | deps |
Closes the four open Dependabot alerts on transitive npm dependencies via pinned pnpm overrides: browserslist (crash on untrusted stats), @xmldom/xmldom (XML fragment injection — its existing override target had itself fallen into the advisory range), @humanfs/node (recursive copy follows symlinks out of the tree) and postcss-selector-parser (AST recursion DoS).