mirror of
https://github.com/Ride-The-Lightning/RTL.git
synced 2026-08-13 12:33:07 +02:00
Apply the bumps from all 20 open Dependabot security PRs (#1583-#1617) in one pass on the release branch: axios 1.16.0, ws 8.21.0, the socket.io server stack, express path-to-regexp, follow-redirects, lodash and the remaining flagged transitive deps. Angular framework packages move in lockstep to 20.3.26 and the CLI/build toolchain to 20.3.32, which drops the vulnerable node-forge from the tree entirely. Also pick up in-range fixes without open PRs (qs, uuid, tough-cookie, cookie, ajv, bn.js, elliptic, socket.io-parser). npm audit: 85 vulnerabilities (23 prod) -> 30 (14 prod). The remainder (request/request-promise, csurf, pdfmake, crypto-browserify chain) needs code changes, not bumps, and is tracked separately. Verified: lint, 199 frontend specs, backend + frontend production builds, and an end-to-end smoke test against the docker regtest fixture (LND, CLN and Eclair auth/getinfo/channels + WS upgrade). |
||
|---|---|---|
| .. | ||
| Release-notes-0.15.9.md | ||