a3336bf346
- graph-ui: bump vite ^6.4.2 -> ^6.4.3 and add overrides pinning the transitive form-data >=4.0.6 and @babel/core >=7.29.6 (all dev-scope build/test deps, not shipped in the binary). Clears the 4 open Dependabot alerts and Scorecard's VulnerabilitiesID. `npm audit` now reports 0 vulnerabilities. - codeql.yml: move `security-events: write` from the workflow top level to the `analyze` job (top level is now `contents: read`), resolving Scorecard's TokenPermissionsID least-privilege finding. CodeQL still uploads results from the job-scoped token. Signed-off-by: Martin Vogel <martin.vogel.tech@gmail.com>