SIGN IN SIGN UP

fix(deps): patch all open Dependabot security vulnerabilities via pnpm overrides (#425)

Adds/updates pnpm overrides to resolve 11 open Dependabot alerts:
- lodash <= 4.17.23 → 4.18.1 (prototype pollution)
- picomatch < 2.3.2 → 2.3.2 and >= 4.0.0 < 4.0.4 → 4.0.4 (ReDoS)
- fast-xml-parser >= 4.0.0-beta.3 <= 5.5.6 → 5.5.10 (multiple vulns)
- flatted < 3.4.2 → 3.4.2 (prototype pollution)

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
J
John Kennedy committed
37a12fa57ed429e37030eb729e6399932d859dfe
Parent: dc030a5
Committed by GitHub <noreply@github.com> on 4/4/2026, 5:10:24 AM