fix(deps): bump the nanoid@^3 override past GHSA-2v37-7h3g-55p8 (#91931)
The repo's own override pinned nanoid@3.3.17 — the exact version GHSA-2v37-7h3g-55p8 / CVE-2026-67213 flags (custom generators loop indefinitely on size 0) — so every fresh install and every npm audit shipped/reported the vulnerable pin no matter what transitives wanted. 3.3.18 is the patched release on the same major. Lockfile re-resolved; npm audit now reports zero nanoid findings, and 3.3.18's zero-size generator returns instead of hanging (verified live). Addresses the upstream-pin quarter of #91931 (mechanism 1 of the reporter's four); the updater-side skip/verify mechanisms and the uv.lock staleness half (#91424) remain tracked there.
This commit is contained in:
+1
-1
@@ -50,7 +50,7 @@
|
||||
"mermaid": "11.16.1",
|
||||
"dompurify": "3.4.13",
|
||||
"ip-address": "10.3.1",
|
||||
"nanoid@^3": "3.3.17",
|
||||
"nanoid@^3": "3.3.18",
|
||||
"nanoid@^6": "6.0.0",
|
||||
"js-yaml@^4": "4.3.1",
|
||||
"undici@^6": "6.28.0",
|
||||
|
||||
Reference in New Issue
Block a user