Summary
Open Dependabot / npm audit findings in website/ need remediation for security and dependency quality.
Current signal
npm audit reports 149 vulnerabilities (2 low, 2 moderate, 144 high, 1 critical)
- Open Dependabot packages include:
body-parser, brace-expansion, dompurify, fast-uri, http-proxy-middleware, js-yaml, postcss, shell-quote, svgo, undici, webpack-dev-server, websocket-driver
Goals
- Update direct and transitive dependencies (via npm overrides/resolutions where needed) to patched versions
- Clear high/critical audit findings where fixes exist
- Keep Docusaurus site build healthy (
npm run build)
- Prefer minimal, reviewable dependency-only changes
Acceptance criteria
Notes
Existing overrides / resolutions in website/package.json are present but several pinned versions are still within vulnerable ranges and need bumping.
Summary
Open Dependabot /
npm auditfindings inwebsite/need remediation for security and dependency quality.Current signal
npm auditreports 149 vulnerabilities (2 low, 2 moderate, 144 high, 1 critical)body-parser,brace-expansion,dompurify,fast-uri,http-proxy-middleware,js-yaml,postcss,shell-quote,svgo,undici,webpack-dev-server,websocket-driverGoals
npm run build)Acceptance criteria
npm auditimproved (ideally no high/critical remaining when fix available)websiteproduction build succeedsNotes
Existing
overrides/resolutionsinwebsite/package.jsonare present but several pinned versions are still within vulnerable ranges and need bumping.