Update Composer and npm dependencies to latest
Composer: ~40 Symfony 7.4.x packages patched to 7.4.17, plus four majors - doctrine/dbal 3->4, phpdocumentor/reflection-docblock 5->6, symfony/mercure-bundle 0.3->0.5, symfony/monolog-bundle 3->4. Removed two doctrine.yaml keys (use_savepoints, report_fields_where_declared) that DBAL 4 deprecated in favor of fixed defaults. npm: @symfony/webpack-encore 4->6, which required bumping its peers webpack-cli 5->6 and sass-loader 14->16 together, plus babel-loader 9->10. Fixes the one high-severity audit finding (RCE in serialize-javascript, via the old css-minimizer-webpack-plugin). One moderate finding remains in webpack-notifier's dev-only notification chain - audit's suggested fix would downgrade it, so left alone; it's build tooling only, never shipped to users. Verified: full test suite green, lint:container clean, both `encore dev` and `npm run build` compile without errors, and the production CSS output was inspected byte-for-byte to confirm the new SVG-minifier warnings (on Bootstrap's pre-encoded icon data-URIs) don't corrupt anything. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
+4
-4
@@ -12,16 +12,16 @@
|
||||
"devDependencies": {
|
||||
"@babel/core": "^7.25.0",
|
||||
"@babel/preset-env": "^7.25.0",
|
||||
"@symfony/webpack-encore": "^4.6.1",
|
||||
"babel-loader": "^9.1.3",
|
||||
"@symfony/webpack-encore": "^6.0.0",
|
||||
"babel-loader": "^10.1.1",
|
||||
"core-js": "^3.37.1",
|
||||
"css-loader": "^7.1.2",
|
||||
"mini-css-extract-plugin": "^2.9.2",
|
||||
"regenerator-runtime": "^0.14.1",
|
||||
"sass": "^1.101.0",
|
||||
"sass-loader": "^14.2.1",
|
||||
"sass-loader": "^16.0.1",
|
||||
"webpack": "^5.95.0",
|
||||
"webpack-cli": "^5.1.4",
|
||||
"webpack-cli": "^6.0.0",
|
||||
"webpack-notifier": "^1.15.0"
|
||||
},
|
||||
"dependencies": {
|
||||
|
||||
Reference in New Issue
Block a user