fix(security): override @xmldom/xmldom to ^0.8.13 (#74) #77
No reviewers
Labels
No labels
autopilot:pending-human
source:analyste
source:defenseur
source:human
source:medic
status:approved
status:blocked
status:in-progress
status:needs-clarification
status:needs-fix
status:ready
status:review
status:triage
type:bug
type:feature
type:infra
type:refactor
type:schema
type:security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: maximus/simpl-liste#77
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/vuln-A-xmldom-override"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Closes #74
Generated autonomously by /autopilot run of 2026-04-24
Summary
Ajoute un override
@xmldom/xmldom: ^0.8.13danspackage.jsonpour corriger 4 CVE HIGH dans la chaine Expo CLI / xcode.CVE corrigees
Verification
package.jsoncontient lentree dansoverridesnpm ls @xmldom/xmldom→0.8.13 overriddendans toutes les chainesnpx tsc --noEmitpasse sans erreurnpm audit --json | jq .vulnerabilities["@xmldom/xmldom"]retournenullpackage-lock.jsonregenere et commit dans le meme commitDecisions (autopilot)
^0.8.13et pas^0.9.0: API compatible, evite le strict parser. Decision prise ce soir (D4).