fix: update vulnerable dependencies
Reviewer automatique — approved
Le fix precedent (overrides globaux) a ete corrige. Seul package-lock.json est modifie via npm audit fix, avec des bumps patch/minor dans les memes versions…
maximus
pushed to fix/simpl-liste-26-vulnerable-deps at maximus/simpl-liste
2026-03-30 06:03:41 +00:00
fix: update vulnerable dependencies
Reviewer automatique — needs-fix
Les overrides globaux avec des versions majeures uniques vont casser les dependances qui attendent des versions majeures anterieures. picomatch>=4.0.4 sera…
fix: update vulnerable dependencies
maximus
created branch fix/simpl-liste-26-vulnerable-deps in maximus/simpl-liste
2026-03-30 04:01:32 +00:00
maximus
pushed to fix/simpl-liste-26-vulnerable-deps at maximus/simpl-liste
2026-03-30 04:01:32 +00:00
rapport catégorie dans le temps
fix: update picomatch 4.0.3 → 4.0.4 (#43)
fix: update vulnerable dependency picomatch
fix: remove expense filter from Category Over Time report (#41)
fix: update picomatch 4.0.3 → 4.0.4 (#43)
Review: APPROVE
Straightforward transitive dependency update fixing 2 HIGH severity vulnerabilities (method injection + ReDoS) in picomatch. The diff is minimal and limited to `package-lock.jso…
fix: update picomatch 4.0.3 → 4.0.4 (#43)
maximus
created branch issue-43-update-picomatch in maximus/Simpl-Resultat
2026-03-30 01:09:38 +00:00
fix: update vulnerable dependency yaml