fix(security): Bump tar to 7.5.9 and lerna to 9.0.4 to fix CVE-2026-26960. (#5824)

* fix(security): Bump tar to 7.5.9 and lerna to 9.0.4 to fix CVE-2026-26960.
Bump sharp to 0.34.5 to fix tar-fs vulnerabilities.

* Update node version to 20.19.0 in circleci config. Needed for lerna and cypress tests.

* Now installing bun for cypress tests in circleci config.

* Use node version 20.19.0 in netlify config.
This commit is contained in:
Joe Boccanfuso authored and GitHub committed 2026-02-18 16:46:02 -05:00
1 parent 8b9cb06115
commit 3d59c0d9d3
8 files changed
+2433 -2028

No files matched your search

+2 -1
View File
@@ -99,6 +99,7 @@
"resolutions": {
"qs": "6.14.1",
"lodash": "4.17.23",
"webpack": "5.105.0"
"webpack": "5.105.0",
"sharp": "0.34.5"
}
}