The dependency-audit job failed on vulnerabilities from `shadcn` and its
transitive tree (hono, fast-uri, body-parser, @modelcontextprotocol/sdk).
`shadcn` is a build-time scaffolding CLI plus a CSS `@import`, never shipped
in the browser bundle, so it belongs in devDependencies.
- move `shadcn` to devDependencies (regenerated lockfile: dev flags only,
no version changes)
- run `npm audit` with `--omit=dev`, matching the runtime-only intent of the
pip-audit step
npm audit --omit=dev --audit-level=high now reports 0 vulnerabilities; the
production build still resolves the shadcn CSS import.
ha-relevant: no