Dalibor Marković
|
4b0456f545
|
upgrade: dependency updates across phases 1-3
Phase 1 - Security:
- lodash 4.17.21 -> 4.18.1 (CVE fix)
- dompurify 3.3.1 -> 3.4.10 (XSS fixes)
- passport 0.4.1 -> 0.7.0 (security fixes)
- remove deprecated request/request-promise, use native fetch instead
- update semver, simple-git, winston, nodemailer
Phase 2 - Light upgrades:
- sass 1.27.0 -> 1.101.0
- chokidar 3.5.3 -> 4.0.3
- mysql2 3.16.0 -> 3.22.5
- pg 8.16.3 -> 8.21.0
- cors, cross-env updates
Phase 3 - Medium risk:
- js-yaml 3.14.0 -> 4.2.0 (safeLoad -> load across 11 files)
- markdown-it 11.0.1 -> 14.2.0 (+7 plugin updates)
- luxon 1.25.0 -> 3.7.2
- fs-extra 9.0.1 -> 11.3.5
- cheerio 1.0.0-rc.5 -> 1.2.0
- highlight.js 10.3.1 -> 11.11.1
18 files changed, 67 insertions, 79 deletions
|
2 weeks ago |