Skip to content

Fix npm dependency security advisories - #10

Merged
realDuang merged 1 commit into
mainfrom
fix/dependabot-alerts
Jun 11, 2026
Merged

Fix npm dependency security advisories#10
realDuang merged 1 commit into
mainfrom
fix/dependabot-alerts

Conversation

@realDuang

Copy link
Copy Markdown
Owner

Summary

  • Refresh dev dependency lockfile entries within existing semver ranges.
  • Add a pnpm override for Vite 6.4.2 so VitePress resolves to the patched Vite line.
  • Resolve local audit findings for vite, esbuild, picomatch, brace-expansion, flatted, minimatch, ajv, diff, and postcss.

Validation

  • pnpm audit
  • pnpm check
  • pnpm test
  • pnpm docs:build
  • VitePress dev server responded with HTTP 200 locally
  • VitePress preview server responded with HTTP 200 locally

@realDuang
realDuang merged commit bfe8483 into main Jun 11, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant