Skip to content

v4.22.4

Choose a tag to compare

@rodrigoslayertech rodrigoslayertech released this 23 Jul 17:54
· 3 commits to main since this release
v4.22.4
3f089bc

Focus: Dependency security — all six Dependabot alerts resolved, npm audit clean.

Changes

  • 🔒 Bumped vulnerable transitive dependencies: linkify-it 5.0.2 and brace-expansion 1.1.16/2.1.2 (high severity ReDoS/DoS advisories), dompurify 3.4.12 and body-parser 1.20.6 (low) via a lockfile refresh, and esbuild 0.28.1 (low, dev-server-only advisory) via an override — @quasar/app-vite 2.6.2 pins the vulnerable range and its 3.x major remains a separate upgrade
  • npm audit: 0 vulnerabilities; 346 tests passing