Commit 713ea0f
committed
fix: use pnpm.overrides to enforce undici >=6.23.0
The top-level `overrides` field is npm syntax; pnpm requires
`pnpm.overrides`. This change ensures undici 5.x (vulnerable to
unbounded decompression, CVE) is not resolved as a transitive dep.1 parent b747434 commit 713ea0f
2 files changed
Lines changed: 7 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
28 | | - | |
29 | | - | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
30 | 32 | | |
31 | 33 | | |
32 | 34 | | |
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments