chore(deps): resolve 22 open Dependabot security alerts - #11
Conversation
Bump next to 15.5.21+ and drizzle-orm to 0.45.2 (SQL injection fix). Add pnpm-workspace overrides for transitive postcss, sharp, undici, and esbuild.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
PR SummaryMedium Risk Overview
Reviewed by Cursor Bugbot for commit 026afbf. Bugbot is set up for automated code reviews on this repo. Configure here. |
Summary
Resolves all 22 open Dependabot security alerts:
^15.5.21(multiple high/medium CVEs)^0.45.2(SQL injection fix insql.identifier()/sql.as())pnpm-workspace.yaml:postcss≥8.5.23,sharp≥0.35.0,undici≥7.29.0,esbuild≥0.25.0Supersedes Dependabot PR #5.
Test plan
pnpm typecheckpnpm ci:qualitypnpm test:unit(36 tests)pnpm ci:build