Skip to content

Commit 713ea0f

Browse files
committed
fix: use pnpm.overrides to enforce undici >=6.23.0
The top-level `overrides` field is npm syntax; pnpm requires `pnpm.overrides`. This change ensures undici 5.x (vulnerable to unbounded decompression, CVE) is not resolved as a transitive dep.
1 parent b747434 commit 713ea0f

2 files changed

Lines changed: 7 additions & 2 deletions

File tree

package.json

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -25,8 +25,10 @@
2525
"@vercel/ncc": "^0.38.4",
2626
"typescript": "^5.9.3"
2727
},
28-
"overrides": {
29-
"undici": ">=6.23.0"
28+
"pnpm": {
29+
"overrides": {
30+
"undici": ">=6.23.0"
31+
}
3032
},
3133
"packageManager": "pnpm@10.29.3"
3234
}

pnpm-lock.yaml

Lines changed: 3 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)