Commit 9b58221
fix: update npm to resolve Trivy CVEs in bundled dependencies
Upgrades npm to latest after Node.js install to patch vulnerable
transitive dependencies (cross-spawn, glob, minimatch, tar).
Chose to update npm rather than upgrade to Node.js 22 to avoid
potential breaking changes for downstream consumers.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>1 parent 675bc66 commit 9b58221
2 files changed
Lines changed: 4 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
64 | 64 | | |
65 | 65 | | |
66 | 66 | | |
| 67 | + | |
| 68 | + | |
67 | 69 | | |
68 | 70 | | |
69 | 71 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
64 | 64 | | |
65 | 65 | | |
66 | 66 | | |
| 67 | + | |
| 68 | + | |
67 | 69 | | |
68 | 70 | | |
69 | 71 | | |
| |||
0 commit comments