chore(deps): update dependencies and fix security vulnerabilities #44

Merged
Keli Grubb merged 2 commits from chore/deps-update-and-audit-fixes into main 2026-08-14 22:27:37 +00:00
Owner

Summary

Updates all out-of-date dependencies and applies npm audit fix to resolve 14 security vulnerabilities (3 critical, 8 high).

Dependency Updates

Package Current → Latest
nuxt 4.4.8 → 4.5.2
mediasoup 3.20.9 → 3.24.2
mediasoup-client 3.21.0 → 3.22.0
hls.js 1.6.16 → 1.7.0
vue 3.5.38 → 3.5.41
vue-router 5.1.0 → 5.2.0
@nuxt/icon 2.2.3 → 2.5.0
eslint 10.5.0 → 10.8.1
vitest / @vitest/coverage-v8 4.1.9 → 4.1.10
ws 8.21.0 → 8.21.3
openid-client 6.8.4 → 6.8.5
fast-xml-parser 5.9.3 → 5.10.1
happy-dom 20.10.6 → 20.11.2
@playwright/test 1.61.1 → 1.62.1
@nuxt/eslint 1.16.0 → 1.17.0
@nuxt/test-utils 4.0.3 → 4.1.0
@iconify-json/tabler 1.2.35 → 1.2.38

Security Audit Fixes (npm audit fix)

  • @nuxt/devtools (critical): Unauthenticated DevTools RPC allows arbitrary command execution on the developer's host
  • tar (critical): Multiple process-crash/DoS vulnerabilities via crafted tar archives
  • esbuild (high): Arbitrary file read when running dev server on Windows
  • brace-expansion (high): Multiple DoS vectors (memory exhaustion, process hang)
  • flatted (high): Prototype pollution via parse()
  • svgo (high): removeScripts plugin leaves executable scripts intact

Verification

  • All 406 tests pass (3 skipped)
  • Lint clean (eslint . --max-warnings 0)
  • npm audit reports 0 vulnerabilities
## Summary Updates all out-of-date dependencies and applies `npm audit fix` to resolve 14 security vulnerabilities (3 critical, 8 high). ### Dependency Updates | Package | Current → Latest | |---|---| | `nuxt` | 4.4.8 → 4.5.2 | | `mediasoup` | 3.20.9 → 3.24.2 | | `mediasoup-client` | 3.21.0 → 3.22.0 | | `hls.js` | 1.6.16 → 1.7.0 | | `vue` | 3.5.38 → 3.5.41 | | `vue-router` | 5.1.0 → 5.2.0 | | `@nuxt/icon` | 2.2.3 → 2.5.0 | | `eslint` | 10.5.0 → 10.8.1 | | `vitest` / `@vitest/coverage-v8` | 4.1.9 → 4.1.10 | | `ws` | 8.21.0 → 8.21.3 | | `openid-client` | 6.8.4 → 6.8.5 | | `fast-xml-parser` | 5.9.3 → 5.10.1 | | `happy-dom` | 20.10.6 → 20.11.2 | | `@playwright/test` | 1.61.1 → 1.62.1 | | `@nuxt/eslint` | 1.16.0 → 1.17.0 | | `@nuxt/test-utils` | 4.0.3 → 4.1.0 | | `@iconify-json/tabler` | 1.2.35 → 1.2.38 | ### Security Audit Fixes (`npm audit fix`) - **`@nuxt/devtools`** (critical): Unauthenticated DevTools RPC allows arbitrary command execution on the developer's host - **`tar`** (critical): Multiple process-crash/DoS vulnerabilities via crafted tar archives - **`esbuild`** (high): Arbitrary file read when running dev server on Windows - **`brace-expansion`** (high): Multiple DoS vectors (memory exhaustion, process hang) - **`flatted`** (high): Prototype pollution via `parse()` - **`svgo`** (high): `removeScripts` plugin leaves executable scripts intact ### Verification - All 406 tests pass (3 skipped) - Lint clean (`eslint . --max-warnings 0`) - `npm audit` reports 0 vulnerabilities
Keli Grubb added 1 commit 2026-08-14 21:57:27 +00:00
chore(deps): update dependencies and fix security vulnerabilities
PR / lint (pull_request) Successful in 27s
PR / test (pull_request) Successful in 26s
PR / docker-build (pull_request) Successful in 38s
PR / e2e (pull_request) Failing after 42s
11951e7348
Dependency updates:
- @nuxt/icon 2.2.3 → 2.5.0
- @nuxt/test-utils 4.0.3 → 4.1.0
- @playwright/test 1.61.1 → 1.62.1
- @vitest/coverage-v8 4.1.9 → 4.1.10
- eslint 10.5.0 → 10.8.1
- fast-xml-parser 5.9.3 → 5.10.1
- happy-dom 20.10.6 → 20.11.2
- hls.js 1.6.16 → 1.7.0
- mediasoup 3.20.9 → 3.24.2
- mediasoup-client 3.21.0 → 3.22.0
- nuxt 4.4.8 → 4.5.2
- openid-client 6.8.4 → 6.8.5
- vue 3.5.38 → 3.5.41
- vue-router 5.1.0 → 5.2.0
- vitest 4.1.9 → 4.1.10
- ws 8.21.0 → 8.21.3
- @iconify-json/tabler 1.2.35 → 1.2.38
- @nuxt/eslint 1.16.0 → 1.17.0

Security audit fixes (npm audit fix):
- @nuxt/devtools: critical - unauthenticated RPC RCE
- tar: critical - multiple DoS/crash vulnerabilities
- esbuild: high - arbitrary file read on Windows
- brace-expansion: high - multiple DoS vectors
- flatted: high - prototype pollution
- svgo: high - removeScripts leaves executable scripts

All 406 tests pass, lint clean, 0 vulnerabilities remaining.
Keli Grubb added 1 commit 2026-08-14 22:16:43 +00:00
fix(ci): bump Playwright container image to v1.62.1-noble
PR / lint (pull_request) Successful in 25s
PR / test (pull_request) Successful in 25s
PR / docker-build (pull_request) Successful in 39s
PR / e2e (pull_request) Successful in 58s
ab8fbeeafa
The e2e job was pinned to mcr.microsoft.com/playwright:v1.61.1-noble,
which has browser binaries incompatible with @playwright/test 1.62.1.
Keli Grubb merged commit cfac12b699 into main 2026-08-14 22:27:37 +00:00
Keli Grubb deleted branch chore/deps-update-and-audit-fixes 2026-08-14 22:27:38 +00:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: keligrubb/kestrelos#44