What's Changed
[8.0.6] - 2026-08-06
Security
- Bump
react-routerfrom 6.30.3 to 8.3.0 (replacingreact-router-dom), which required upgradingreact/react-domfrom 18 to 19 (react-router v8 peer requirement), to mitigate CVE-2026-40181, CVE-2026-53666, CVE-2026-53668, CVE-2026-53669, and GHSA-qwww-vcr4-c8h2 - Bump
sharpfrom 0.34.5 to 0.35.3 to mitigate GHSA-f88m-g3jw-g9cj - Bump
aws-cdk-libfrom 2.248.0 to 2.263.0 to mitigate CVE-2026-13760 and GHSA-464c-974j-9xm6 - Bump
postcssfrom 8.5.10 to 8.5.23 to mitigate CVE-2026-45623, CVE-2026-69153, and GHSA-r28c-9q8g-f849 - Bump
brace-expansionfrom 1.1.13 to 1.1.18 to mitigate CVE-2026-13149, CVE-2026-14257, and CVE-2026-45149 - Bump
systeminformationfrom 5.31.5 to 5.33.1 to mitigate CVE-2026-44724 and CVE-2026-50289 - Bump
wsfrom 8.20.0 to 8.21.0 to mitigate CVE-2026-45736 and CVE-2026-48779 - Bump
vitefrom 6.4.2 to 6.4.3 to mitigate CVE-2026-53571 and CVE-2026-53632 - Bump
vitestfrom 3.2.4 to 3.2.6 to mitigate CVE-2026-47429 - Bump
js-yamlfrom 3.14.2 to 3.15.0 to mitigate CVE-2026-53550 and CVE-2026-59869 - Bump
form-datafrom 4.0.5 to 4.0.6 to mitigate CVE-2026-12143 - Bump
js-cookiefrom 3.0.5 to 3.0.7 to mitigate CVE-2026-46625 - Bump
morganfrom 1.10.1 to 1.11.0 to mitigate CVE-2026-5078 - Bump
adm-zipfrom 0.5.16 to 0.6.0 to mitigate CVE-2026-39244 - Bump
tmpfrom 0.2.5 to 0.2.6 to mitigate CVE-2026-44705 - Bump
body-parserfrom 1.20.4 to 1.20.6 to mitigate CVE-2026-12590 - Bump
esbuildfrom 0.27.7 to 0.28.1 to mitigate GHSA-g7r4-m6w7-qqqr - Bump
qsfrom 6.15.1 to 6.15.3 to mitigate CVE-2026-8723 - Bump
uuidfrom 8.3.2 to 11.1.1 to mitigate CVE-2026-41907