Lockfile-level update of the packages trivy flags on main, all within their current major: - next 16.3.1 -> 16.3.3 (CVE-2026-75604, CRITICAL) - js-yaml 4.3.1 -> 4.3.2 (CVE-2026-84375) - nodemailer 9.0.5 -> 9.1.1 (GHSA-2x7j-588g-ccc2, GHSA-8m3c-c648-2xjj) - sharp 0.35.3 -> 0.35.5 (GHSA-rgj7-g3m4-5g8c) - undici 6.28.0 -> 6.29.0 (CVE-2026-19534) - brace-expansion -> 1.1.21 / 2.1.7 (CVE-2026-102276, CVE-2026-102278, dev) - minimatch 9.0.5 -> 9.0.9 (CVE-2026-26996/27903/27904, dev) next, js-yaml and nodemailer were exact-pinned, so their pins move too. PINNED_DEPS in the antipattern guard follows nodemailer to 9.1.1; without it the pinned-dep guard fails. Remaining: nodemailer GHSA-v53p-9fqp-m79j is only fixed in 10.x (major bump of a direct dependency, left for a separate reviewed change). Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>