chore: resolve high-severity npm audit advisories

The dependency-audit CI step (npm audit --audit-level=high) was failing
on pre-existing transitive advisories. Force patched versions via
overrides and bump vite to a patched 7.x:

- esbuild ^0.28.1  (GHSA-g7r4-m6w7-qqqr, high)
- form-data ^4.0.6 (GHSA-hmw2-7cc7-3qxx, high)
- vite ^7.3.5      (GHSA-v6wh-96g9-6wx3 / GHSA-fx2h-pf6j-xcff, high)

Audit now passes at --audit-level=high (only a low @babel/core and
moderate js-yaml remain, both below the gate and build/dev-time only;
js-yaml is a direct dep so it can't be overridden). Build + full test
suite (1130) green on the bumped toolchain.

ha-relevant: no
This commit is contained in:
Pouzor
2026-06-17 16:49:25 +02:00
parent 6fba0cdec4
commit 0796c96fc1
2 changed files with 123 additions and 121 deletions
+4 -2
View File
@@ -38,7 +38,9 @@
"zustand": "^5.0.11"
},
"overrides": {
"hono": "^4.12.21"
"hono": "^4.12.21",
"esbuild": "^0.28.1",
"form-data": "^4.0.6"
},
"devDependencies": {
"@eslint/js": "^9.39.1",
@@ -61,7 +63,7 @@
"tailwindcss": "^4.2.1",
"typescript": "~5.9.3",
"typescript-eslint": "^8.48.0",
"vite": "^7.3.1",
"vite": "^7.3.5",
"vitest": "^4.0.18"
}
}