fix(deps): bump the nanoid@^3 override past GHSA-2v37-7h3g-55p8 (#91931)

The repo's own override pinned nanoid@3.3.17 — the exact version
GHSA-2v37-7h3g-55p8 / CVE-2026-67213 flags (custom generators loop
indefinitely on size 0) — so every fresh install and every npm audit
shipped/reported the vulnerable pin no matter what transitives wanted.
3.3.18 is the patched release on the same major. Lockfile re-resolved;
npm audit now reports zero nanoid findings, and 3.3.18's zero-size
generator returns instead of hanging (verified live).

Addresses the upstream-pin quarter of #91931 (mechanism 1 of the
reporter's four); the updater-side skip/verify mechanisms and the
uv.lock staleness half (#91424) remain tracked there.
This commit is contained in:
Teknium
2026-08-26 15:10:32 -07:00
parent 2812d6121b
commit 8fdda828a8
2 changed files with 7 additions and 7 deletions
+1 -1
View File
@@ -50,7 +50,7 @@
"mermaid": "11.16.1",
"dompurify": "3.4.13",
"ip-address": "10.3.1",
"nanoid@^3": "3.3.17",
"nanoid@^3": "3.3.18",
"nanoid@^6": "6.0.0",
"js-yaml@^4": "4.3.1",
"undici@^6": "6.28.0",