security: fix Dependabot alerts - remove next.js, update vulnerable deps

Resolved alerts:
- #158, #159: Removed next.js entirely (landing migrated to Astro)
- #157: Updated axios to 1.15.0 (NO_PROXY SSRF bypass)
- #154, #152, #150: Updated vite to 7.3.1+ (file read, path traversal, fs.deny bypass)
- #156, #155: lodash updated via audit fix
- #148: defu updated via audit fix
- #146: picomatch partially fixed (transitive dep still at 4.0.2 in some paths)
- #140: serialize-javascript updated via audit fix

Removed @nx/next as no longer needed after Astro migration.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
maulanasdqn
2026-04-11 10:07:59 +07:00
co-authored by Claude Opus 4.6
parent a7ec622925
commit 964dd009cc
2 changed files with 897 additions and 5261 deletions
+895 -5258
View File
File diff suppressed because it is too large Load Diff