Commit 9fb62e6
authored
Merge pull request #2677 from cfpb/security-severe-and-high
Security updates for high and critical vulnerabilities.
## Changes
- updates jspdf to 4.0.0
- updates glob to 11.1.0
- updates tar to at least 7.5.6
- bump ansi-html to 0.0.9
- updates qs to at least 6.14.1
- qs is used by vite-plugin-node-polyfills (which has been updated)
- but we'd need to move to the next major version of cypress to update its qs dependency. I made a ticket for it over in GHE #5410
## Testing
1. Does it look good on staging? Yes!
2. Are tests passing? Yep!
## Screenshot
#### On staging as `v3.3.11-rc2`
<img width="832" height="728" alt="Screenshot 2026-01-26 at 8 00 41 AM" src="https://github.com/user-attachments/assets/e63311f0-7189-4c8f-be41-547e85746ddc" />2 files changed
+60
-164
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
47 | 47 | | |
48 | 48 | | |
49 | 49 | | |
50 | | - | |
| 50 | + | |
51 | 51 | | |
52 | 52 | | |
53 | 53 | | |
| |||
114 | 114 | | |
115 | 115 | | |
116 | 116 | | |
117 | | - | |
| 117 | + | |
118 | 118 | | |
119 | 119 | | |
120 | 120 | | |
121 | 121 | | |
122 | | - | |
| 122 | + | |
123 | 123 | | |
124 | 124 | | |
125 | 125 | | |
| |||
138 | 138 | | |
139 | 139 | | |
140 | 140 | | |
141 | | - | |
| 141 | + | |
142 | 142 | | |
143 | 143 | | |
144 | 144 | | |
145 | | - | |
| 145 | + | |
| 146 | + | |
146 | 147 | | |
147 | 148 | | |
148 | 149 | | |
0 commit comments