fix(deps): override html-to-text to 10.0.1 to clear CVE-2026-40345 (#1832)
Trivy's daily sca scan fails on deepmerge-ts 7.1.5 (HIGH, fixed in 8.0.0), pulled in via mailparser's exact pin on html-to-text 10.0.0. Upstream html-to-text 10.0.1 is a patch release that bumps deepmerge-ts to ^8.0.1; the override lifts it to 8.0.2. Only consumer is mailparser's simpleParser in the invoice-inbox extension. Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
150e2a3f14
commit
7db47defbc
@@ -105,6 +105,7 @@
|
||||
"vitest": "^4.1.9"
|
||||
},
|
||||
"overrides": {
|
||||
"html-to-text": "10.0.1",
|
||||
"ws": "^8.21.0",
|
||||
"sharp": "^0.35.3",
|
||||
"postcss": "^8.5.18"
|
||||
|
||||
Reference in New Issue
Block a user