v2.9.3 Strict Dependency & Template Security Hardening
Strict Dependency & Template Security Hardening:
js-yamlDoS & Compatibility Fix: Pinnedjs-yamlto^4.3.2in package overrides acrosspackage.jsonandtemplates/common/package.json.ejs, fixing quadratic CPU consumption advisories (GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj) while preserving full compatibility withjest@30.4.2and preventing forced dependency downgrades.brace-expansionDoS Mitigation: Updatedbrace-expansionoverride to^5.0.9(GHSA-3jxr-9vmj-r5cp, GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895), eliminating exponential-time CPU loop vulnerability.- Daily Template Audit Hardening: Added strict overrides for
body-parser(^1.20.6),ip-address(^10.5.0),shell-quote(^1.10.0),undici(^6.28.0),semver(^7.7.1), and upgradedmongooseto^8.24.4andsnykto^1.1307.0to maintain a pristine 0-vulnerability baseline indaily-audit.yml.
Full Changelog: v2.9.2...v2.9.3