Commit 99fea0f
committed
Fix 5 high-severity vulnerabilities
Changes in docs/:
- package.json: added a sharp override (^0.35.3) since next's own optional dep still points to a vulnerable libvips-based sharp build.
- package-lock.json: next bumped to 16.2.12, postcss to 8.5.25, sharp to 0.35.3, plus transitive brace-expansion/js-yaml bumps — all within existing semver ranges, no code changes needed.
Build (npm run build) still passes. Nothing was committed — let me know if you want that pushed.1 parent 3606851 commit 99fea0f
3 files changed
Lines changed: 291 additions & 202 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
0 commit comments