chore(sync): synchronize origin/main brand logos & CI peer-deps fix into forgejo/main #66

Merged
A-Guevara merged 5 commits from sync/main-v3-sync into main 2026-10-06 00:18:20 +00:00
Owner

Unifies GitHub main and Forgejo main with release v3.0.0.

Unifies GitHub main and Forgejo main with release v3.0.0.
feat(brand): add high-quality transparent TTI logos under 10KB for M365 and web resources
Some checks failed
scan / trivy-fs (push) Failing after 1m3s
baseline-security / baseline (push) Failing after 1m13s
561c641777
feat(brand): add dual-mode keyline TTI logo (<10KB) for M365 Copilot Chat
Some checks failed
scan / trivy-fs (push) Failing after 56s
baseline-security / baseline (push) Failing after 1m7s
d26170a69f
feat(brand): upgrade keyline logo to bold 4.5px stroke for M365 Copilot Chat
Some checks failed
scan / trivy-fs (push) Failing after 51s
baseline-security / baseline (push) Failing after 1m1s
03923db873
Merge origin/main into main: unify brand logos and 3.0.0 prime-time release
Some checks failed
publish-package / publish (push) Failing after 23s
6ad86e173b
fix(ci): enable legacy-peer-deps in .npmrc and deploy-pages workflow to resolve tiptap ERESOLVE
Some checks failed
publish-package / publish (push) Failing after 22s
scan / trivy-fs (push) Failing after 1m35s
ai-review / review (pull_request) Successful in 1m27s
baseline-security / baseline (push) Failing after 2m0s
scan / trivy-fs (pull_request) Failing after 1m26s
baseline-security / baseline (pull_request) Failing after 2m0s
20006f25ea

🔧 Security-gate fix map

The gate failed on these dependency findings — fastest path to green for each:

finding package installed → fixed do this
CVE-2026-63671 (HIGH) @nuxtjs/mdc 0.21.1 → 0.22.1 merge #59 — fix(security): @nuxtjs/mdc ^0.22.2 (CVE-2026-63671) — hold f
CVE-2026-102276 (HIGH) brace-expansion 5.0.9 → 5.0.10, 3.0.7, 2.1.5, 1.1.19 merge #62 — chore(deps): update dependency brace-expansion to v5.0.12 [s
CVE-2026-102278 (HIGH) brace-expansion 5.0.9 → 5.0.11, 3.0.8, 2.1.6, 1.1.20 merge #62 — chore(deps): update dependency brace-expansion to v5.0.12 [s
CVE-2026-93687 (HIGH) braces 3.0.3 → ? no fix PR yet — npm update braces --package-lock-only
CVE-2026-92708 (HIGH) devalue 5.8.2 → 5.9.3 no fix PR yet — npm update devalue --package-lock-only
GHSA-mcm9-63f2-9j32 (HIGH) devalue 5.8.2 → 5.9.3 no fix PR yet — npm update devalue --package-lock-only
GHSA-r9w8-h9r3-54w4 (HIGH) devalue 5.8.2 → 5.9.3 no fix PR yet — npm update devalue --package-lock-only
GHSA-x5rw-q4pp-hg5g (HIGH) devalue 5.8.2 → 5.9.3 no fix PR yet — npm update devalue --package-lock-only
CVE-2026-84375 (HIGH) js-yaml 4.3.1 → 4.3.2, 3.15.2 no fix PR yet — npm update js-yaml --package-lock-only
CVE-2026-85393 (HIGH) node-forge 1.4.0 → ? no fix PR yet — npm update node-forge --package-lock-only
GHSA-rgj7-g3m4-5g8c (HIGH) sharp 0.35.3 → 0.35.4 no fix PR yet — npm update sharp --package-lock-only
CVE-2026-84370 (HIGH) svgo 4.0.2 → 2.8.4, 3.3.5, 4.1.0 no fix PR yet — npm update svgo --package-lock-only
CVE-2026-19534 (HIGH) undici 8.10.0 → 6.28.1, 7.29.1, 8.10.2 no fix PR yet — npm update undici --package-lock-only
CVE-2026-84961 (HIGH) undici 8.10.0 → 7.29.1, 8.10.2 no fix PR yet — npm update undici --package-lock-only
CVE-2026-85152 (HIGH) undici 8.10.0 → 8.10.2 no fix PR yet — npm update undici --package-lock-only

Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.

### 🔧 Security-gate fix map <!-- tti-fixmap:20006f25eab108bf0daf517bee6d5b6e529a0781 --> The gate failed on these dependency findings — fastest path to green for each: | finding | package | installed → fixed | do this | |---|---|---|---| | CVE-2026-63671 (HIGH) | `@nuxtjs/mdc` | 0.21.1 → 0.22.1 | merge #59 — fix(security): @nuxtjs/mdc ^0.22.2 (CVE-2026-63671) — hold f | | CVE-2026-102276 (HIGH) | `brace-expansion` | 5.0.9 → 5.0.10, 3.0.7, 2.1.5, 1.1.19 | merge #62 — chore(deps): update dependency brace-expansion to v5.0.12 [s | | CVE-2026-102278 (HIGH) | `brace-expansion` | 5.0.9 → 5.0.11, 3.0.8, 2.1.6, 1.1.20 | merge #62 — chore(deps): update dependency brace-expansion to v5.0.12 [s | | CVE-2026-93687 (HIGH) | `braces` | 3.0.3 → ? | no fix PR yet — `npm update braces --package-lock-only` | | CVE-2026-92708 (HIGH) | `devalue` | 5.8.2 → 5.9.3 | no fix PR yet — `npm update devalue --package-lock-only` | | GHSA-mcm9-63f2-9j32 (HIGH) | `devalue` | 5.8.2 → 5.9.3 | no fix PR yet — `npm update devalue --package-lock-only` | | GHSA-r9w8-h9r3-54w4 (HIGH) | `devalue` | 5.8.2 → 5.9.3 | no fix PR yet — `npm update devalue --package-lock-only` | | GHSA-x5rw-q4pp-hg5g (HIGH) | `devalue` | 5.8.2 → 5.9.3 | no fix PR yet — `npm update devalue --package-lock-only` | | CVE-2026-84375 (HIGH) | `js-yaml` | 4.3.1 → 4.3.2, 3.15.2 | no fix PR yet — `npm update js-yaml --package-lock-only` | | CVE-2026-85393 (HIGH) | `node-forge` | 1.4.0 → ? | no fix PR yet — `npm update node-forge --package-lock-only` | | GHSA-rgj7-g3m4-5g8c (HIGH) | `sharp` | 0.35.3 → 0.35.4 | no fix PR yet — `npm update sharp --package-lock-only` | | CVE-2026-84370 (HIGH) | `svgo` | 4.0.2 → 2.8.4, 3.3.5, 4.1.0 | no fix PR yet — `npm update svgo --package-lock-only` | | CVE-2026-19534 (HIGH) | `undici` | 8.10.0 → 6.28.1, 7.29.1, 8.10.2 | no fix PR yet — `npm update undici --package-lock-only` | | CVE-2026-84961 (HIGH) | `undici` | 8.10.0 → 7.29.1, 8.10.2 | no fix PR yet — `npm update undici --package-lock-only` | | CVE-2026-85152 (HIGH) | `undici` | 8.10.0 → 8.10.2 | no fix PR yet — `npm update undici --package-lock-only` | <sub>Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.</sub>
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
tti/tti-ux!66
No description provided.