0.46.4 — dependency security bumps
Dependency security bumps
Ships the fixes from e812929 into the published images (no functional change).
- client —
dompurify3.4.12 → 3.4.14 (bundled into the runtime via jspdf); build toolingfast-uri→ 4.1.2,nanoid→ 3.3.18,brace-expansion→ 5.0.9. - docs —
pymdown-extensions→ 11.0.1,mkdocs-materialfloor → 9.7 (9.6 caps pymdown at<11).
Resolves Dependabot alerts GHSA-7p8r-x3mc-p8w7 (fast-uri), GHSA-55q2-fjhq-7xh7 (dompurify), GHSA-gm37-52c6-37mw (pymdown-extensions), plus two latent audit highs — GHSA-2v37-7h3g-55p8 (nanoid) and GHSA-rgw5-rvv9-x895 (brace-expansion). pnpm audit clean · client build + 43 tests green · docs resolve verified on PyPI.
🐳 ghcr.io/dim145/figurecollector-{server,client,docs}:0.46.4
📝 Full changelog: 0.46.3...0.46.4