-
Update dependencies to latest versions - drager, pull/1536
-
Security workflow permissions fixes - drager
-
Bump ring from 0.17.8 to 0.17.14 - dependabot, pull/1516
-
Bump brace-expansion from 1.1.11 to 1.1.12 in /npm - dependabot, pull/1515
-
Bump rustls from 0.23.16 to 0.23.18 - dependabot, pull/1451
-
Fix tar vulnerability (CVE-2026-23745) in npm package
Override tar dependency to ^7.5.3 to fix arbitrary file overwrite and symlink poisoning vulnerability (GHSA-8qq5-rm4j-mr97).
-
Fix axios vulnerabilities in npm package
Override axios dependency to ^0.30.0 to fix SSRF/credential leakage via absolute URL and XSRF-TOKEN leakage (CSRF) vulnerabilities.