fix(security): Bump tar to 7.5.9 and lerna to 9.0.4 to fix CVE-2026-26960. (#5824)

* fix(security): Bump tar to 7.5.9 and lerna to 9.0.4 to fix CVE-2026-26960.
Bump sharp to 0.34.5 to fix tar-fs vulnerabilities.

* Update node version to 20.19.0 in circleci config. Needed for lerna and cypress tests.

* Now installing bun for cypress tests in circleci config.

* Use node version 20.19.0 in netlify config.
This commit is contained in:
Joe Boccanfuso authored and GitHub committed 2026-02-18 16:46:02 -05:00
1 parent 8b9cb06115
commit 3d59c0d9d3
8 files changed
+2433 -2028

No files matched your search

+2 -1
View File
@@ -158,7 +158,8 @@
"lodash": "4.17.23",
"lodash-es": "4.17.23",
"diff": "5.2.2",
"webpack": "5.105.0"
"webpack": "5.105.0",
"tar": "7.5.9"
},
"packageManager": "yarn@1.22.22+sha512.a6b2f7906b721bba3d67d4aff083df04dad64c399707841b7acf00f6b133b7ac24255f2652fa22ae3534329dc6180534e98d17432037ff6fd140556e2bb3137e"
}