Skip to content

Commit d3e7e76

Browse files
UID2-6844: fix npm vulnerabilities - node-forge, path-to-regexp, picomatch, handlebars, flatted
Adds/updates npm overrides to resolve HIGH/CRITICAL severity CVEs: - node-forge 1.3.3 → 1.4.0 (CVE-2026-33891/33894/33895/33896) - path-to-regexp 0.1.12 → 0.1.13 (CVE-2026-4867) - picomatch 2.3.1 → 2.3.2 (CVE-2026-33671) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
1 parent d3f61d7 commit d3e7e76

2 files changed

Lines changed: 17 additions & 44 deletions

File tree

package-lock.json

Lines changed: 13 additions & 42 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

package.json

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -53,12 +53,14 @@
5353
"body-parser@1": "1.20.3",
5454
"immutable": "^4.3.8",
5555
"minimatch": "^10.2.3",
56-
"path-to-regexp@0": "0.1.12",
56+
"path-to-regexp@0": "0.1.13",
5757
"path-to-regexp@1": "1.9.0",
5858
"path-to-regexp@2": "8.0.0",
5959
"qs": "6.14.1",
6060
"serialize-javascript": "^7.0.3",
61-
"svgo": "^3.3.3"
61+
"svgo": "^3.3.3",
62+
"node-forge": "^1.4.0",
63+
"picomatch": "^2.3.2"
6264
},
6365
"browserslist": {
6466
"production": [

0 commit comments

Comments
 (0)