Skip to content

Commit bae33bb

Browse files
author
Claude Bot
committed
Security: update vulnerable dependencies and align overrides with 26_1
- Align pnpm.overrides with 26_1 branch for cherry-pick compatibility - Add 50+ security overrides for transitive dependencies - Add overrides for vite@5, webpack-dev-server, react-router, @babel/helpers, @babel/runtime, js-yaml, storybook, and Angular 19.x - Update node-forge, tar, rollup, qs, axios override ranges - Reduces pnpm audit from 201 to 16 vulnerabilities - Remaining 16 are unfixable: Angular 17.x (6), babel-traverse, terser, request, esbuild, parcel, elliptic
1 parent 9a742dd commit bae33bb

File tree

2 files changed

+7525
-8890
lines changed

2 files changed

+7525
-8890
lines changed

package.json

Lines changed: 66 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -64,18 +64,81 @@
6464
],
6565
"pnpm": {
6666
"overrides": {
67-
"@devexpress/callsite-record@^4.1.6": "4.1.6",
67+
"@devexpress/callsite-record@^4.1.6": "4.1.7",
68+
"basic-ftp@<5.2.0": "~5.2.0",
69+
"@isaacs/brace-expansion@<=5.0.0": "^5.0.1",
70+
"@modelcontextprotocol/sdk@>=1.10.0 <=1.25.3": "^1.26.0",
6871
"form-data@<2.5.4": "2.5.5",
6972
"form-data@>=4.0.0 <4.0.4": "^4.0.5",
7073
"pbkdf2@<=3.1.2": "^3.1.3",
7174
"sha.js@<=2.4.11": "^2.4.12",
7275
"rollup@<2.79.2": "^4.53.3",
76+
"rollup@>=4.0.0 <4.59.0": "^4.59.0",
7377
"json5@<1.0.2": "^2.2.3",
74-
"axios@<1.8.2": "^1.13.2",
78+
"axios@<=1.13.4": "^1.13.5",
7579
"braces@<3.0.3": "^3.0.3",
7680
"semver@<5.7.2": "^5.7.2",
81+
"qs": ">=6.14.2",
7782
"glob@>=10.2.0 <10.5.0": "^10.5.0",
78-
"node-forge@<1.3.2": "^1.3.2"
83+
"node-forge@<1.4.0": "1.4.0",
84+
"vite@>=6.0.0 <6.4.1": "^6.4.1",
85+
"tar@<=7.5.9": "^7.5.10",
86+
"underscore@<=1.13.7": "^1.13.8",
87+
"hono@<4.12.4": "^4.12.4",
88+
"@hono/node-server@<1.19.10": "^1.19.10",
89+
"express-rate-limit@>=8.2.0 <8.2.2": "^8.2.2",
90+
"immutable@>=5.0.0 <5.1.5": "^5.1.5",
91+
"minimatch@<3.1.5": "3.1.5",
92+
"minimatch@>=4.0.0 <4.2.5": "4.2.5",
93+
"minimatch@>=5.0.0 <5.1.8": "5.1.8",
94+
"minimatch@>=9.0.0 <9.0.7": "9.0.9",
95+
"minimatch@>=10.0.0 <10.2.4": "10.2.4",
96+
"picomatch@>=2.0.0 <2.3.2": "2.3.2",
97+
"picomatch@>=4.0.0 <4.0.4": "4.0.4",
98+
"path-to-regexp@0.1.12": "0.1.13",
99+
"path-to-regexp@>=8.0.0 <8.4.0": "8.4.0",
100+
"serialize-javascript@<=7.0.2": "7.0.5",
101+
"flatted@<3.4.0": "^3.4.0",
102+
"undici@<7.24.0": "^7.24.0",
103+
"socket.io-parser@>=4.0.0 <4.2.6": "^4.2.6",
104+
"lodash@<4.18.1": "4.18.1",
105+
"lodash.template@<4.18.1": "4.18.1",
106+
"bn.js@<4.12.3": "4.12.3",
107+
"bn.js@>=5.0.0 <5.2.3": "5.2.3",
108+
"brace-expansion@<1.1.13": "1.1.13",
109+
"brace-expansion@>=2.0.0 <2.0.3": "2.0.3",
110+
"cookie@<0.7.0": "^0.7.0",
111+
"diff@>=4.0.0 <4.0.4": "4.0.4",
112+
"diff@>=5.0.0 <5.2.2": "5.2.2",
113+
"dompurify@<=3.3.1": "^3.3.2",
114+
"@eslint/plugin-kit@<0.3.4": "^0.3.4",
115+
"http-proxy-middleware@>=1.3.0 <2.0.9": "^2.0.9",
116+
"immutable@>=4.0.0-rc.1 <4.3.8": "^4.3.8",
117+
"jspdf@<=4.2.0": "^4.2.1",
118+
"js-yaml@>=4.0.0 <4.1.1": "^4.1.1",
119+
"micromatch@<4.0.8": "^4.0.8",
120+
"nanoid@<3.3.8": "^3.3.8",
121+
"on-headers@<1.1.0": "^1.1.0",
122+
"ajv@<6.14.0": "6.14.0",
123+
"ajv@>=7.0.0-alpha.0 <8.18.0": "^8.18.0",
124+
"yaml@>=1.0.0 <1.10.3": "1.10.3",
125+
"yaml@>=2.0.0 <2.8.3": "2.8.3",
126+
"tmp@<=0.2.3": "^0.2.4",
127+
"@tootallnate/once@<3.0.1": "^3.0.1",
128+
"tough-cookie@<4.1.3": "^4.1.3",
129+
"webpack@>=5.49.0 <=5.104.0": "^5.104.1",
130+
"vite@>=5.0.0 <=5.4.20": "^5.4.21",
131+
"webpack-dev-server@<=5.2.0": "^5.2.1",
132+
"react-router@>=6.0.0 <6.30.2": "^6.30.2",
133+
"@remix-run/router@<=1.23.1": "^1.23.2",
134+
"@babel/helpers@<7.26.10": "^7.26.10",
135+
"@babel/runtime@<7.26.10": "^7.26.10",
136+
"js-yaml@<3.14.2": "3.14.2",
137+
"@angular/common@>=19.0.0 <19.2.16": "^19.2.20",
138+
"@angular/core@>=19.0.0-next.0 <19.2.20": "^19.2.20",
139+
"@angular/compiler@>=19.0.0-next.0 <19.2.20": "^19.2.20",
140+
"@angular/platform-server@>=19.0.0-next.0 <19.2.20": "^19.2.20",
141+
"storybook@>=10.0.0-beta.0 <10.2.10": "^10.2.10"
79142
}
80143
},
81144
"packageManager": "pnpm@9.15.4"

0 commit comments

Comments
 (0)