v4.22.4
Focus: Dependency security — all six Dependabot alerts resolved, npm audit clean.
Changes
- 🔒 Bumped vulnerable transitive dependencies:
linkify-it5.0.2 andbrace-expansion1.1.16/2.1.2 (high severity ReDoS/DoS advisories),dompurify3.4.12 andbody-parser1.20.6 (low) via a lockfile refresh, andesbuild0.28.1 (low, dev-server-only advisory) via an override —@quasar/app-vite2.6.2 pins the vulnerable range and its 3.x major remains a separate upgrade - ✅
npm audit: 0 vulnerabilities; 346 tests passing