Skip to content

Fix dependency security vulnerabilities across the project#1095

Open
ThyeeZz wants to merge 1 commit intopreviewfrom
resolve-security-alerts
Open

Fix dependency security vulnerabilities across the project#1095
ThyeeZz wants to merge 1 commit intopreviewfrom
resolve-security-alerts

Conversation

@ThyeeZz
Copy link
Copy Markdown
Contributor

@ThyeeZz ThyeeZz commented Apr 17, 2026

  • Upgrade next-mdx-remote from v5 to v6 with blockJS/blockDangerousJS flags
  • Remove unused html-word-count dependency (eliminates minimist critical CVEs)
  • Upgrade jimp from v0.22 to v1.6.1 with API migration (crop, write, require)
  • Apply npm audit fix for axios, follow-redirects, underscore, undici, lodash, etc.

- Upgrade next-mdx-remote from v5 to v6 with blockJS/blockDangerousJS flags
- Remove unused html-word-count dependency (eliminates minimist critical CVEs)
- Upgrade jimp from v0.22 to v1.6.1 with API migration (crop, write, require)
- Apply npm audit fix for axios, follow-redirects, underscore, undici, lodash, etc.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant