chore: update transitive dependencies for security fixes
Summary
- Update package-lock.json to pull in latest versions of transitive dependencies
- elliptic 6.6.1 (security fix)
- body-parser 1.20.4 (security fix)
- cookie 0.7.2, express 4.22.1, cookie-parser 1.4.7
This supersedes the following dependabot PRs which can be closed:
- #728 (elliptic 6.6.0)
- #727 (cookie, cookie-parser, express, express-session)
- #726 (body-parser 1.20.3)
Test plan
- [x] Lint passes
- [ ] CI tests pass
Closes #728 Closes #727 Closes #726
🤖 Worlddriven Status
📊 Live Status Dashboard
🗓️ Merge Date: 2025-12-16 at 18:07:57 UTC (today) 📅 Started: 2025-12-13 at 21:09:04 UTC ⚡ Speed Factor: 0.41 (59% faster due to reviews) ✅ Positive votes: 478/811 contribution weight (coefficient: 0.59) 📈 Base Merge Time: 7 days → Current: 3 days
🎯 Want to influence when this merges?
Your review matters! As a contributor to this project, your voice helps determine the merge timeline.
How to review:
-
Check the changes

-
Leave your review

Your options:
-
✅ Agree & Speed Up:
Approving makes this merge faster
-
❌ Disagree & Slow Down:
Requesting changes delays the merge
💡 Pro tip: The more contributors who agree, the faster this gets merged!
📊 View detailed stats on the dashboard
📋 Recent Activity
• 2025-12-13, 21:09:11 - Pull request opened • 2025-12-16, 18:51:14 - Pull request merged by worlddriven ✅
This comment is automatically updated by worlddriven