Files
Keli GrubbandMadison Grubb cfac12b699
Push / release (push) Successful in 12s
Push / publish (push) Successful in 37s
chore(deps): update dependencies and fix security vulnerabilities (#44)
## Summary

Updates all out-of-date dependencies and applies `npm audit fix` to resolve 14 security vulnerabilities (3 critical, 8 high).

### Dependency Updates

| Package | Current → Latest |
|---|---|
| `nuxt` | 4.4.8 → 4.5.2 |
| `mediasoup` | 3.20.9 → 3.24.2 |
| `mediasoup-client` | 3.21.0 → 3.22.0 |
| `hls.js` | 1.6.16 → 1.7.0 |
| `vue` | 3.5.38 → 3.5.41 |
| `vue-router` | 5.1.0 → 5.2.0 |
| `@nuxt/icon` | 2.2.3 → 2.5.0 |
| `eslint` | 10.5.0 → 10.8.1 |
| `vitest` / `@vitest/coverage-v8` | 4.1.9 → 4.1.10 |
| `ws` | 8.21.0 → 8.21.3 |
| `openid-client` | 6.8.4 → 6.8.5 |
| `fast-xml-parser` | 5.9.3 → 5.10.1 |
| `happy-dom` | 20.10.6 → 20.11.2 |
| `@playwright/test` | 1.61.1 → 1.62.1 |
| `@nuxt/eslint` | 1.16.0 → 1.17.0 |
| `@nuxt/test-utils` | 4.0.3 → 4.1.0 |
| `@iconify-json/tabler` | 1.2.35 → 1.2.38 |

### Security Audit Fixes (`npm audit fix`)

- **`@nuxt/devtools`** (critical): Unauthenticated DevTools RPC allows arbitrary command execution on the developer's host
- **`tar`** (critical): Multiple process-crash/DoS vulnerabilities via crafted tar archives
- **`esbuild`** (high): Arbitrary file read when running dev server on Windows
- **`brace-expansion`** (high): Multiple DoS vectors (memory exhaustion, process hang)
- **`flatted`** (high): Prototype pollution via `parse()`
- **`svgo`** (high): `removeScripts` plugin leaves executable scripts intact

### Verification

- All 406 tests pass (3 skipped)
- Lint clean (`eslint . --max-warnings 0`)
- `npm audit` reports 0 vulnerabilities

---------

Co-authored-by: Madison Grubb <madison@elastiflow.com>
Reviewed-on: #44
2026-08-14 22:27:36 +00:00
..