Dashboard › craft › Distillation
2d6f7c11-64ac-48fb-9fd6-fb42e0956875["51e3be3cf9b56d1676ec0cd720267b0f","47722804e336d47a1ae5702eb6ad44f1","ce1b945b350cff56b402b82168946665","1e36fa642aed6f755b6ed48d5065e29a","25267ebe61cdfded51d7c93faa8da920","59c8d78c565b080123b6bd1021768c97","ca2730110f2a7b9a01434227a6e7f0f9","bbc923545cafcba026ef3e756d9d0e42","5510fdf465f12abce242986fa303dc60","251628fb147d3d5da910a67f9287eb06","0308d717e1c154deb34573b1d456f738","caf2e0450506a3680b55c76d351cb891"]
Date: July 28, 2026
brace-expansion CVE-2026-13149 (high) fixed via override brace-expansion: ^5.0.8 + minimatch → ^10.2.6 (resolves 5.0.8). Docs sharp GHSA-f88m-g3jw-g9cj (high) ^0.33.5→^0.35.0→0.35.3; astro 3 CVEs ^5.16.11→^7.1.4→7.1.4 + @astrojs/starlight ^0.37.3→^0.41.5 (needed astro ^7.0.2); svgo alert was stale (lockfile already 4.0.1, patched) resolved by refresh.tsc --noEmit (root project) EXIT 0 — clean.master. Recent master commits: 67eb802 fix: resolve 10 Dependabot security alerts (#836), 8f37246 build(deps-dev): bump esbuild from 0.25.12 to 0.28.1 (#834), 6a353dc meta: Bump new development version.singleQuote: true, arrowParens: avoid. prettier --check warns on pnpm-lock.yaml and docs/pnpm-lock.yaml (Code style issues found in 2 files) in working tree.fix/dependabot-security-alerts: 22efc12 fix: use ^ specifiers and drop @tootallnate/once override; then dropped (stash@{0} = 9f63a988538c230da2f1e861812fb1aea64aa8d7). Used to test baseline prettier.--check on COMMITTED/baseline lockfiles ALSO warns on pnpm-lock.yaml and docs/pnpm-lock.yaml — confirmed pre-existing false positive, not introduced by this change. CI tolerates/excludes lockfiles from prettier.