chore/deps-update-and-audit-fixes
main
Updates all out-of-date dependencies and applies npm audit fix to resolve 14 security vulnerabilities (3 critical, 8 high).
npm audit fix
nuxt
mediasoup
mediasoup-client
hls.js
vue
vue-router
@nuxt/icon
eslint
vitest
@vitest/coverage-v8
ws
openid-client
fast-xml-parser
happy-dom
@playwright/test
@nuxt/eslint
@nuxt/test-utils
@iconify-json/tabler
@nuxt/devtools
tar
esbuild
brace-expansion
flatted
parse()
svgo
removeScripts
eslint . --max-warnings 0
npm audit
Dependency updates: - @nuxt/icon 2.2.3 → 2.5.0 - @nuxt/test-utils 4.0.3 → 4.1.0 - @playwright/test 1.61.1 → 1.62.1 - @vitest/coverage-v8 4.1.9 → 4.1.10 - eslint 10.5.0 → 10.8.1 - fast-xml-parser 5.9.3 → 5.10.1 - happy-dom 20.10.6 → 20.11.2 - hls.js 1.6.16 → 1.7.0 - mediasoup 3.20.9 → 3.24.2 - mediasoup-client 3.21.0 → 3.22.0 - nuxt 4.4.8 → 4.5.2 - openid-client 6.8.4 → 6.8.5 - vue 3.5.38 → 3.5.41 - vue-router 5.1.0 → 5.2.0 - vitest 4.1.9 → 4.1.10 - ws 8.21.0 → 8.21.3 - @iconify-json/tabler 1.2.35 → 1.2.38 - @nuxt/eslint 1.16.0 → 1.17.0 Security audit fixes (npm audit fix): - @nuxt/devtools: critical - unauthenticated RPC RCE - tar: critical - multiple DoS/crash vulnerabilities - esbuild: high - arbitrary file read on Windows - brace-expansion: high - multiple DoS vectors - flatted: high - prototype pollution - svgo: high - removeScripts leaves executable scripts All 406 tests pass, lint clean, 0 vulnerabilities remaining.
The e2e job was pinned to mcr.microsoft.com/playwright:v1.61.1-noble, which has browser binaries incompatible with @playwright/test 1.62.1.
No dependencies set.
The note is not visible to the blocked user.
Summary
Updates all out-of-date dependencies and applies
npm audit fixto resolve 14 security vulnerabilities (3 critical, 8 high).Dependency Updates
nuxtmediasoupmediasoup-clienthls.jsvuevue-router@nuxt/iconeslintvitest/@vitest/coverage-v8wsopenid-clientfast-xml-parserhappy-dom@playwright/test@nuxt/eslint@nuxt/test-utils@iconify-json/tablerSecurity Audit Fixes (
npm audit fix)@nuxt/devtools(critical): Unauthenticated DevTools RPC allows arbitrary command execution on the developer's hosttar(critical): Multiple process-crash/DoS vulnerabilities via crafted tar archivesesbuild(high): Arbitrary file read when running dev server on Windowsbrace-expansion(high): Multiple DoS vectors (memory exhaustion, process hang)flatted(high): Prototype pollution viaparse()svgo(high):removeScriptsplugin leaves executable scripts intactVerification
eslint . --max-warnings 0)npm auditreports 0 vulnerabilities