Skip to content

Commit 5f77d8b

Browse files
Fix NPM vulnerabilites (#5459)
1 parent d7d8f01 commit 5f77d8b

3 files changed

Lines changed: 13 additions & 26 deletions

File tree

.github/copilot-instructions.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,3 +9,5 @@
99
- After updating, verify: `npm run compile` (build), `npm run lint` (lint), `npm audit` (security)
1010
- The ESLint packages (`eslint`, `@eslint/js`, `typescript-eslint`, `eslint-config-prettier`) should be updated together
1111
- Fix any new lint warnings from updates to ESLint
12+
- Use `npm audit` to identify vulnerabilities
13+
- Do not use `npm audit fix --force` when a vulnerability is in a transitive dependency, instead add an `overrides` entry

package-lock.json

Lines changed: 7 additions & 26 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

package.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -94,6 +94,10 @@
9494
"typescript": "^6.0.2",
9595
"typescript-eslint": "^8.58.0"
9696
},
97+
"overrides": {
98+
"serialize-javascript": "^7.0.5",
99+
"diff": "^8.0.3"
100+
},
97101
"extensionDependencies": [
98102
"vscode.powershell"
99103
],

0 commit comments

Comments
 (0)