security: fix Dependabot alerts - remove next.js, update vulnerable deps
Resolved alerts: - #158, #159: Removed next.js entirely (landing migrated to Astro) - #157: Updated axios to 1.15.0 (NO_PROXY SSRF bypass) - #154, #152, #150: Updated vite to 7.3.1+ (file read, path traversal, fs.deny bypass) - #156, #155: lodash updated via audit fix - #148: defu updated via audit fix - #146: picomatch partially fixed (transitive dep still at 4.0.2 in some paths) - #140: serialize-javascript updated via audit fix Removed @nx/next as no longer needed after Astro migration. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
a7ec622925
commit
964dd009cc
Generated
+895
-5258
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user