Skip to content

[debt] Resolve npm audit advisories (8 high, 10 moderate, 1 low) #76

@zwrose

Description

@zwrose

npm audit reports 19 advisories at baseline (8 high, 10 moderate, 1 low). Most are transitive build/test tooling. Triage and resolve (npm audit fix, targeted bumps, or assess reachability).

High:

  • flatted (high)
  • glob (high)
  • lodash (high)
  • minimatch (high)
  • next (high)
  • picomatch (high)
  • rollup (high)
  • vite (high)

Moderate:

  • ajv (moderate)
  • brace-expansion (moderate)
  • esbuild (moderate)
  • js-yaml (moderate)
  • next-auth (moderate)
  • postcss (moderate)
  • tsx (moderate)
  • uuid (moderate)
  • ws (moderate)
  • yaml (moderate)

Low:

  • @eslint/plugin-kit (low)

Note: dependency bumps were deliberately deferred during the redesign (Chunk 0 §0d triages non-test debt rather than fixing it). Schedule separately.


Surfaced by /audit-debt on 2026-05-28.

Metadata

Metadata

Assignees

No one assigned

    Labels

    tech-debtSurfaced by /audit-debt sweep

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions