fix(deps): clear all npm audit vulnerabilities (27 → 0)

- Remove unused docx4js (only a stale comment referenced it); drops the
  vulnerable transitive xml2js prototype-pollution chain
- Upgrade sharp 0.34 -> 0.35.4 for the libvips CVEs (GHSA-f88m-g3jw-g9cj);
  resize/format API surface unchanged, @img/@napi-rs asarUnpack globs still
  match the new prebuilt layout
- npm audit fix for the rest: electron 41.10.7 (protocol/iframe fixes),
  electron-builder chain (AppImage search-path + updater token leak),
  dompurify 3.4.14, mermaid 11.17.2, tar (PAX parsing, critical), tmp,
  js-yaml, brace-expansion, browserslist, fast-uri, form-data, ip-address,
  nanoid, fflate, @xmldom/xmldom, @babel/core and others

613/613 tests green; lint clean; npm audit reports 0 vulnerabilities
This commit is contained in:
2026-09-05 20:52:08 +05:30
parent c4dcbd8caf
commit efca458495
3 changed files with 942 additions and 2105 deletions
+1 -2
View File
@@ -74,7 +74,6 @@
"codemirror": "^6.0.2",
"core-util-is": "^1.0.3",
"docx": "^9.6.0",
"docx4js": "^2.0.1",
"dompurify": "^3.3.1",
"electron-store": "^10.1.0",
"ffmpeg-static": "^5.3.0",
@@ -89,7 +88,7 @@
"pdfjs-dist": "^5.5.207",
"pdfkit": "^0.17.2",
"pizzip": "^3.2.0",
"sharp": "^0.34.3",
"sharp": "^0.35.4",
"simple-git": "^3.32.3",
"tslib": "^2.8.1"
},