Skip to content

Patch transitive build dependencies - #4

Merged
daniel-techAI merged 1 commit into
mainfrom
agent/patch-transitive-advisories
Aug 2, 2026
Merged

Patch transitive build dependencies#4
daniel-techAI merged 1 commit into
mainfrom
agent/patch-transitive-advisories

Conversation

@daniel-techAI

Copy link
Copy Markdown
Owner

Summary

  • force Next's vulnerable transitive PostCSS 8.4.31 to patched 8.5.25
  • force optional Sharp 0.34.5 to patched 0.35.3
  • regenerate the npm lockfile

Why

GitHub reported GHSA advisories that cannot be resolved by updating Next because 16.2.12 is the current latest release and still pins the affected ranges.

Validation

  • npm audit: 0 vulnerabilities
  • lockfile resolves PostCSS 8.5.25 and Sharp 0.35.3
  • diff check passed
  • full Linux quality/build/Playwright workflow is the merge gate

@daniel-techAI
daniel-techAI merged commit 11dfc23 into main Aug 2, 2026
1 check passed
@daniel-techAI
daniel-techAI deleted the agent/patch-transitive-advisories branch August 2, 2026 12:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant