fix(security): Bump tar to 7.5.9 and lerna to 9.0.4 to fix CVE-2026-26960. (#5824)
* fix(security): Bump tar to 7.5.9 and lerna to 9.0.4 to fix CVE-2026-26960. Bump sharp to 0.34.5 to fix tar-fs vulnerabilities. * Update node version to 20.19.0 in circleci config. Needed for lerna and cypress tests. * Now installing bun for cypress tests in circleci config. * Use node version 20.19.0 in netlify config.
This commit is contained in:
1 parent
8b9cb06115
commit
3d59c0d9d3
8 files changed
+2433
-2028
No files matched your search
@@ -19,7 +19,7 @@
|
||||
[build.environment]
|
||||
# If 'production', `yarn install` does not install devDependencies
|
||||
NODE_ENV = "development"
|
||||
NODE_VERSION = "20.18.1"
|
||||
NODE_VERSION = "20.19.0"
|
||||
YARN_VERSION = "1.22.5"
|
||||
RUBY_VERSION = "2.6.2"
|
||||
YARN_FLAGS = "--no-ignore-optional --pure-lockfile"
|
||||
|
||||
Reference in new issue
Block a user