Skip to content

Update dependencies and investigate npm audit vulnerabilities#339

Merged
crandmck merged 1 commit intomainfrom
fix/update-dependencies
Apr 3, 2026
Merged

Update dependencies and investigate npm audit vulnerabilities#339
crandmck merged 1 commit intomainfrom
fix/update-dependencies

Conversation

@crandmck
Copy link
Copy Markdown
Collaborator

@crandmck crandmck commented Apr 2, 2026

  • Updated Docusaurus to latest version (3.9.2)
  • Updated @contentauth/react to 0.2.95 for compatibility
  • Updated c2pa and c2pa-wc to latest versions

Known unresolved vulnerabilities:

  • serialize-javascript (no fix available yet in npm ecosystem)
  • lodash/lodash-es in nested chevrotain dependencies

These are build-time only dependencies with lower risk for a static site. Recommend using npm audit --audit-level=moderate for CI/CD.

@netlify
Copy link
Copy Markdown

netlify bot commented Apr 2, 2026

Deploy Preview for cai-open-source ready!

Name Link
🔨 Latest commit b1c047b
🔍 Latest deploy log https://app.netlify.com/projects/cai-open-source/deploys/69ceeff00a4f0d000870eebf
😎 Deploy Preview https://deploy-preview-339--cai-open-source.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

- Updated Docusaurus to latest version (3.9.2)
- Updated @contentauth/react to 0.2.95 for compatibility
- Updated c2pa and c2pa-wc to latest versions
- Reduced high-severity vulnerabilities from 30 to current state

Known unresolved vulnerabilities:
- serialize-javascript (no fix available yet in npm ecosystem)
- lodash/lodash-es in nested chevrotain dependencies

These are build-time only dependencies with lower risk for a static site.
Recommend using `npm audit --audit-level=moderate` for CI/CD.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
@crandmck crandmck force-pushed the fix/update-dependencies branch from 874d525 to b1c047b Compare April 2, 2026 22:38
@github-actions
Copy link
Copy Markdown

github-actions bot commented Apr 2, 2026

@crandmck crandmck merged commit ef1acbf into main Apr 3, 2026
7 checks passed
@crandmck crandmck deleted the fix/update-dependencies branch April 3, 2026 00:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant