Files
accounted/scripts
Claude CodeandClaude Sonnet 5.5 0250b4bab2
masterplan-lock / check (push) Successful in 6s
masterplan-lock / check (pull_request) Successful in 33s
fix(deps): patch HIGH/CRITICAL advisories
Lockfile-level update of the packages trivy flags on main, all within
their current major:

- next 16.3.1 -> 16.3.3 (CVE-2026-75604, CRITICAL)
- js-yaml 4.3.1 -> 4.3.2 (CVE-2026-84375)
- nodemailer 9.0.5 -> 9.1.1 (GHSA-2x7j-588g-ccc2, GHSA-8m3c-c648-2xjj)
- sharp 0.35.3 -> 0.35.5 (GHSA-rgj7-g3m4-5g8c)
- undici 6.28.0 -> 6.29.0 (CVE-2026-19534)
- brace-expansion -> 1.1.21 / 2.1.7 (CVE-2026-102276, CVE-2026-102278, dev)
- minimatch 9.0.5 -> 9.0.9 (CVE-2026-26996/27903/27904, dev)

next, js-yaml and nodemailer were exact-pinned, so their pins move too.
PINNED_DEPS in the antipattern guard follows nodemailer to 9.1.1; without
it the pinned-dep guard fails.

Remaining: nodemailer GHSA-v53p-9fqp-m79j is only fixed in 10.x (major
bump of a direct dependency, left for a separate reviewed change).

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-09-30 17:17:51 +02:00
..