security(deps): bump @sveltejs/kit and vite to clear 5 high CVEs
Bumps @sveltejs/kit 2.55.0→2.60.1, vite 7.3.1→7.3.3, and all patched transitives. Clears GHSA-3f6h-2hrp-w5wx, GHSA-2crg-3p73-43xp, GHSA-4w7w-66w2-5vf9, GHSA-v2wj-q39q-566r, GHSA-p9ff-h696-f583. Residual: cookie <0.7.0 (LOW) via @sveltejs/kit peer chain — upstream fix requires @sveltejs/kit@0.0.30, a breaking downgrade. Tracked as known residual per issue #458 acceptance criteria note. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2832
frontend/package-lock.json
generated
2832
frontend/package-lock.json
generated
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user