+ "fcf6d37fed143781a6260f12b6dae1b729b1b1e7": "web/ui: bump sanitize-html in mantine-ui to v2.17.4 [SECURITY]\n\nThe previous commit on this branch only refreshed the legacy react-app\nlockfile, leaving the mantine-ui workspace lockfile pinned at\nsanitize-html 2.17.3 \u2014 which is in the affected range of CVE-2026-44990\n/ GHSA-rpr9-rxv7-x643 (CVSS 9.3 critical, default-config XSS via the\n<xmp> raw-text passthrough). Bump the declared range in\nweb/ui/mantine-ui/package.json from ^2.17.3 to ^2.17.4 and refresh the\nworkspace-root lockfile so the modern UI is patched too.\n\nThe lockfile delta is small because the mantine-ui workspace was already\non htmlparser2 v10 and dayjs via other deps; the only new transitive\naddition is launder 1.7.1 (now a direct dependency of sanitize-html).\n\n```release-notes\n[SECURITY] Update sanitize-html to v2.17.4 to fix CVE-2026-44990 (XSS via the <xmp> raw-text passthrough) in the bundled mantine-ui and react-app UIs.\n```\n\nSigned-off-by: Arve Knudsen <arve.knudsen@gmail.com>"
0 commit comments