fix(deps): override html-to-text to 10.0.1 to clear CVE-2026-40345 (#1832)

Trivy's daily sca scan fails on deepmerge-ts 7.1.5 (HIGH, fixed in 8.0.0),
pulled in via mailparser's exact pin on html-to-text 10.0.0. Upstream
html-to-text 10.0.1 is a patch release that bumps deepmerge-ts to ^8.0.1;
the override lifts it to 8.0.2. Only consumer is mailparser's simpleParser
in the invoice-inbox extension.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Mattsson
2026-08-24 14:14:23 +02:00
committed by GitHub
co-authored by Claude Fable 5
parent 150e2a3f14
commit 7db47defbc
2 changed files with 19 additions and 8 deletions
+1
View File
@@ -105,6 +105,7 @@
"vitest": "^4.1.9"
},
"overrides": {
"html-to-text": "10.0.1",
"ws": "^8.21.0",
"sharp": "^0.35.3",
"postcss": "^8.5.18"