Security

Dependency security audit and updates

We've completed a full dependency security audit as part of our quarterly review.

Results

ActionCount
Packages updated23
Packages removed5
Vulnerabilities patched8
New dev dependencies2

Key changes

  • Upgraded next from 15.x to 16.0 (includes security patches)

  • Removed lodash — replaced usage with native ES2024 methods

  • Pinned all dependencies to exact versions (no ^ or ~)

  • Added npm audit to our CI pipeline — builds fail on high/critical vulnerabilities

Automated scanning

We now run:

  1. npm audit on every pull request

  2. Dependabot for automated security PRs

  3. Socket.dev for supply chain attack detection

We run these audits quarterly. The next one is scheduled for October 2025.