Add and update npm overrides to resolve high and moderate severity
vulnerabilities in transitive dependencies:
- tar: upgrade to ^7.5.11 (GHSA-9ppj-qmqm-q256, high - symlink path traversal)
- picomatch: upgrade to ^4.0.4 (GHSA-c2c7-rcm5-vvqj, high - ReDoS;
GHSA-3v7f-55p6-f55p, medium - method injection)
- serialize-javascript: upgrade override to ^7.0.5 (GHSA-qj8w-gfj5-8c6v,
medium - CPU exhaustion DoS)
- brace-expansion: upgrade to ^2.0.3 and ^1.1.13 (GHSA-f886-m6hf-6m8v,
medium - process hang and memory exhaustion)
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Summary
using npm overrides
GHSA-3v7f-55p6-f55p, medium — method injection)
exhaustion DoS)
process hang and memory exhaustion)
Test plan
patched versions are installed
🤖 Generated with Claude Code