fix(security): Bump tar to 7.5.9 and lerna to 9.0.4 to fix CVE-2026-26960. (#5824)

* fix(security): Bump tar to 7.5.9 and lerna to 9.0.4 to fix CVE-2026-26960.
Bump sharp to 0.34.5 to fix tar-fs vulnerabilities.

* Update node version to 20.19.0 in circleci config. Needed for lerna and cypress tests.

* Now installing bun for cypress tests in circleci config.

* Use node version 20.19.0 in netlify config.
This commit is contained in:
Joe Boccanfuso authored and GitHub committed 2026-02-18 16:46:02 -05:00
1 parent 8b9cb06115
commit 3d59c0d9d3
8 files changed
+2433 -2028

No files matched your search

+2 -5
View File
@@ -6,7 +6,7 @@ orbs:
defaults: &defaults
docker:
- image: cimg/node:20.18.1
- image: cimg/node:20.19.0
environment:
TERM: xterm
QUICK_BUILD: true
@@ -121,10 +121,6 @@ jobs:
# Define ignored vulnerabilities with comments
IGNORED_VULNS=(
"GHSA-5j98-mcp5-4vw2" # CVE-2025-64756 - glob is not used on the command line
"GHSA-8qq5-rm4j-mr97" # CVE-2026-23745 - limited to build/dev environments
"GHSA-r6q2-hw4h-h46w" # CVE-2026-23950 - limited to build/dev environments
"GHSA-34x7-hfp2-rc4v" # CVE-2026-24842 - limited to build/dev environments
)
# Build ignore flags
@@ -374,6 +370,7 @@ jobs:
resource_class: large
parallelism: 8
steps:
- install_bun
- run:
name: Install System Dependencies
command: |