* update deps to latest and pin min node & npm version * checkin lock files * make server serve client to merge both into one in order to reduce complexity * adjust CSP accordingly