From fb656e8e35cb5ea1196619bb6bf729ea48a86084 Mon Sep 17 00:00:00 2001 From: snekxs Date: Tue, 6 Oct 2026 00:56:25 -0600 Subject: [PATCH] fix(deps): bump source-map-js to 1.2.2 for GHSA-68fv-2mgg-jv7q npm audit --audit-level=high reports one high-severity advisory: source-map-js allows event-loop denial of service through indexed source-map section offsets. It is a dev-only transitive dependency (via vite/postcss) and is present at every protocol pin, so the hourly Update Mouse Protocol workflow fails at its audit step: the app stays pinned to 0.24.0 even though 0.26.0 is published, which keeps the newly merged AJAZZ, Redragon M690 PRO and Lamzu Paro Aurora drivers unreachable in the panel. npm audit fix moves source-map-js 1.2.1 -> 1.2.2. Audit is clean, npm run check passes 290/290 and npm run size stays inside the budget. --- package-lock.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/package-lock.json b/package-lock.json index c16d4deb..b558c051 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1111,9 +1111,9 @@ } }, "node_modules/source-map-js": { - "version": "1.2.1", - "resolved": "https://registry.npmjs.org/source-map-js/-/source-map-js-1.2.1.tgz", - "integrity": "sha512-UXWMKhLOwVKb728IUtQPXxfYU+usdybtUrK/8uGE8CQMvrhOpwvzDBwj0QhSL7MQc7vIsISBG8VQ8+IDQxpfQA==", + "version": "1.2.2", + "resolved": "https://registry.npmjs.org/source-map-js/-/source-map-js-1.2.2.tgz", + "integrity": "sha512-KGj/8Y43x35aZVDtt+J4mK1hoLGHULMYfSkODJNQjNDC3oW1PqPoxMwo0pLUsWM/UEGzON/NxeHywEfNXNP3Vw==", "dev": true, "license": "BSD-3-Clause", "engines": {