🔒 Fix open Dependabot security alerts

Bump transitive deps to patched versions (source-map-js, dompurify,
brace-expansion, @fastify/busboy, @grpc/grpc-js) and add npm overrides
for the two that parents pin to vulnerable ranges: mermaid's nested
katex now dedupes to the root katex, and @tailwindcss/typography uses
postcss-selector-parser ^7.1.6.

Compiled CSS and vendored assets are unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Nuno CoraçãoandClaude Opus 5.5 committed 2026-10-07 17:02:38 +01:00
1 parent 9b173140ce
commit 59fc919de8
3 files changed
+618 -1050

No files matched your search

+8
View File
@@ -119,5 +119,13 @@
"@heroicons/react": "^2.2.0",
"@tailwindcss/forms": "^0.5.11",
"commander": "^15.0.0"
},
"overrides": {
"mermaid": {
"katex": "$katex"
},
"@tailwindcss/typography": {
"postcss-selector-parser": "^7.1.6"
}
}
}