mirror of
https://github.com/tiennm99/DocsGPT.git
synced 2026-10-05 00:13:01 +00:00
Lockfile-only update; package.json is unchanged. extensions/react-widget is published as the npm package `docsgpt` and as an HTML embed, so its production dependency tree reaches every consumer. That tree carried 5 advisories (2 high, 2 moderate, 1 low), 7 across the full tree. dompurify 3.4.0 -> 3.4.13 (moderate, XSS) js-yaml 4.1.1 -> 4.3.1 (high, quadratic-complexity DoS) linkify-it 5.0.0 -> 5.0.2 (high) markdown-it 14.1.0 -> 14.3.0 (moderate) svgo 4.0.1 -> 4.0.2 (high, dev) brace-expansion 1.1.12 -> 1.1.18 (high, CVE-2026-13149; nested copies) @babel/core 7.29.0 -> 7.29.7 (low) npm audit goes 7 -> 0 (production tree 5 -> 0). Verified locally: clean npm ci, `npm run build` (embed) and `npm run build:react` (library) both build, npm run lint and tsc --noEmit pass.