Updated npm packages to latest semver-compatible versions. 4 remaining high-severity vulns are dev-only (serialize-javascript in vite-plugin-pwa chain). 515/515 tests pass, zero type errors, build clean. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>