mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 11:12:35 +02:00
Frontend: - react-router/-dom 7.18.1 -> 7.18.2. The RSC-mode CSRF advisory was carried as a documented exception in the audit gate because its only fix was the 8.3.0 major; upstream backported it, so the exemption lapsed on its own -- an entry only holds while fixAvailable.isSemVerMajor is true. The allowlist is now empty; the machinery stays for the next one. - dompurify 3.4.12 -> 3.4.13. Ships in the app, but the path is unreachable: no hooks registered, IN_PLACE never used. - js-yaml override ^4.3.0 -> ^5.2.3 (fix not backported below 5.x, so a major) and nanoid override ^3.3.18. Both dev-only, via eslint and postcss. eslintrc calls only load(), on the legacy .eslintrc.yml path this repo does not use; eslint, vite build and 2861 frontend tests pass on it. Backend: - cryptography >=48.0.1 -> >=50.0.0, aiohttp >=3.14.0 -> >=3.14.3, pyopenssl >=26.3.0 -> >=26.4.0. CI resolves from scratch and was already installing the fixed releases; the floors cover the case CI does not, an existing venv where >= is satisfied and `pip install -r` upgrades nothing. pyOpenSSL has to move with cryptography -- each release caps it to a narrow window, so a stale pyOpenSSL pins cryptography below its own fix line.