Security fixes (27 → 0 vulnerabilities):
- npm audit fix: @babel/helpers, ajv, brace-expansion, cross-spawn, flatted,
js-yaml, lodash, picomatch, semver, tough-cookie, word-wrap
- Upgrade jest 27 → 29, ts-jest 27 → 29, @types/jest 27 → 29 to eliminate
jest-environment-jsdom/jsdom/@tootallnate/once vulnerability chain
- Upgrade markdownlint-cli2 ^0.5.1 → ^0.22.1 (fixes markdown-it, micromatch,
yaml vulnerabilities)
- Update form-data 4.0.0 → ^4.0.5 (critical: unsafe random boundary)
- Upgrade typescript ^4.6 → ^5 and @types/node ^16 → ^18 for compatibility
Build/test fixes for upgraded deps:
- Update jest snapshot format for jest@29 serializer
- Add typeRoots and types to tsconfig.build.json to prevent TypeScript from
picking up stray types from parent node_modules directories
- Bump version to 3.0.9-jci2