14-Jul-2026 — resolve open Dependabot vulnerability alerts ref #316

build 776commit c6f16c2


Clears all 14 open Dependabot alerts (3 high, 7 medium, 4 low) with four dependency changes, plus a fifth pre-emptive fix.

The direct nodemailer pin (9.0.3) was never vulnerable: all eight nodemailer alerts were against the stale 6.9.16 copy nested under mailparser 3.7.2. Bumping mailparser drops that copy along with the vulnerable linkify-it, so a single bump clears ten alerts.

npm audit reports 0 vulnerabilities in both projects. Server typecheck clean, 879 server unit tests passing, production Angular build succeeds, and exceljs xlsx write/read round-trips correctly against uuid 11.