fix: resolve npm audit high severity vulnerabilities (#1347)

- Upgrade fast-xml-parser to 5.10.1 (fixes GHSA-8r6m-32jq-jx6q)
- Add package.json override to force brace-expansion >=5.0.8 across
  all transitive dependencies (fixes GHSA-mh99-v99m-4gvg) without
  downgrading jest/ts-jest
- Refresh .licenses/npm cache to match updated dependency tree
- Rebuild dist/setup and dist/cache-save

npm audit now reports 0 vulnerabilities. Pre-existing test suite
failures (7 suites, ESM/jest teardown issue) verified unrelated to
this change - identical on unmodified main with node 24.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
Haritha
2026-08-03 11:18:19 -05:00
committed by GitHub
parent 5fda3b95a4
commit 8549b9f8f5
15 changed files with 2247 additions and 1490 deletions
+3
View File
@@ -8,6 +8,9 @@
"engines": {
"node": ">=24.0.0"
},
"overrides": {
"brace-expansion": "^5.0.8"
},
"scripts": {
"build": "ncc build -o dist/setup src/setup-python.ts && ncc build -o dist/cache-save src/cache-save.ts",
"format": "prettier --no-error-on-unmatched-pattern --write \"**/*.{ts,yml,yaml}\"",