Commit 9d42bde
committed
fix: resolve 17 high/critical Dependabot security alerts
- Update semantic-kernel[azure] from 1.28.0 to 1.40.0 (CVE: InMemoryVectorStore RCE, Arbitrary File Write)
- Add npm overrides to fix transitive dependency vulnerabilities:
- serialize-javascript >=7.0.3 (RCE via RegExp.flags)
- bfj >=9.1.3 (removes vulnerable jsonpath dependency)
- underscore >=1.13.8 (DoS via unlimited recursion)
- svgo >=3.3.3 (DoS via Billion Laughs)
- d3-color and nth-check pinned to top-level safe versions
- Remove duplicate d3-color and lodash-es entries in package.json
- Regenerate package-lock.json with all overrides applied1 parent 88ee0c8 commit 9d42bde
File tree
3 files changed
+921
-1258
lines changed- docs/workshop/docs/workshop
- src/App
3 files changed
+921
-1258
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
5 | | - | |
| 5 | + | |
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
| |||
0 commit comments