From 2c2a19a60f2dc504d4f65b8c026dcac62ca0beff Mon Sep 17 00:00:00 2001 From: "aikido-autofix[bot]" <119856028+aikido-autofix[bot]@users.noreply.github.com> Date: Sat, 13 Dec 2025 18:23:15 +0000 Subject: [PATCH 1/2] fix(security): update glob from 11.0.3 to 11.1.0 --- package.json | 7 ++++++- pnpm-lock.yaml | 28 ++++++++-------------------- 2 files changed, 14 insertions(+), 21 deletions(-) diff --git a/package.json b/package.json index a41028f..44d370d 100644 --- a/package.json +++ b/package.json @@ -80,5 +80,10 @@ "dist", "public", "LICENCE" - ] + ], + "pnpm": { + "overrides": { + "glob@<=11.1.0": "11.1.0" + } + } } diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 56dbc14..8ade43b 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -4,6 +4,9 @@ settings: autoInstallPeers: true excludeLinksFromLockfile: false +overrides: + glob@<=11.1.0: 11.1.0 + importers: .: @@ -1562,8 +1565,8 @@ packages: resolution: {integrity: sha512-XxwI8EOhVQgWp6iDL+3b0r86f4d6AX6zSU55HfB4ydCEuXLXc5FcYeOu+nnGftS4TEju/11rt4KJPTMgbfmv4A==} engines: {node: '>=10.13.0'} - glob@11.0.3: - resolution: {integrity: sha512-2Nim7dha1KVkaiF4q6Dj+ngPPMdfvLJEOpZk/jKiUAkqKebpGAWQXAq9z1xu9HKu5lWfqw/FASuccEjyznjPaA==} + glob@11.1.0: + resolution: {integrity: sha512-vuNwKSaKiqm7g0THUBu2x7ckSs3XJLXE+2ssL7/MfTGPLLcrJQ/4Uq1CjPTtO5cCIiRxqvN6Twy1qOwhL0Xjcw==} engines: {node: 20 || >=22} hasBin: true @@ -1791,10 +1794,6 @@ packages: lowlight@3.3.0: resolution: {integrity: sha512-0JNhgFoPvP6U6lE/UdVsSq99tn6DhjjpAj5MxG49ewd2mOBVtwWYIT8ClyABhq198aXXODMU6Ox8DrGy/CpTZQ==} - lru-cache@11.0.2: - resolution: {integrity: sha512-123qHRfJBmo2jXDbo/a5YOQrJoHF/GNQTLzQ5+IdK5pWpceK17yRc6ozlWd25FxvGKQbIUs91fDFkXmDHTKcyA==} - engines: {node: 20 || >=22} - lru-cache@11.2.4: resolution: {integrity: sha512-B5Y16Jr9LB9dHVkh6ZevG+vAbOsNOYCX+sXvFWFu7B3Iz5mijW3zdbMyhsh8ANd2mSWBYdJgnqi+mL7/LrOPYg==} engines: {node: 20 || >=22} @@ -2023,10 +2022,6 @@ packages: path-parse@1.0.7: resolution: {integrity: sha512-LDJzPVEEEPR+y48z93A0Ed0yXb8pAByGWo/k5YYdYgpY2/2EsOsksJrq7lOHxryrVOn1ejG6oAp8ahvOIQD8sw==} - path-scurry@2.0.0: - resolution: {integrity: sha512-ypGJsmGtdXUOeM5u93TyeIEfEhM6s+ljAhrk5vAvSx8uyY/02OvrZnA0YNGUrPXfpJMgI1ODd3nwz8Npx4O4cg==} - engines: {node: 20 || >=22} - path-scurry@2.0.1: resolution: {integrity: sha512-oWyT4gICAu+kaA7QWk/jvCHWarMKNs6pXOGWKDTr7cw4IGcUbW+PeTfbaQiLGheFRpjo6O9J0PmyMfQPjH71oA==} engines: {node: 20 || >=22} @@ -3050,7 +3045,7 @@ snapshots: content-disposition: 0.5.4 fastify-plugin: 5.0.1 fastq: 1.17.1 - glob: 11.0.3 + glob: 11.1.0 '@fastify/swagger-ui@5.2.3': dependencies: @@ -4275,14 +4270,14 @@ snapshots: dependencies: is-glob: 4.0.3 - glob@11.0.3: + glob@11.1.0: dependencies: foreground-child: 3.3.1 jackspeak: 4.1.1 minimatch: 10.1.1 minipass: 7.1.2 package-json-from-dist: 1.0.1 - path-scurry: 2.0.0 + path-scurry: 2.0.1 glob@13.0.0: dependencies: @@ -4561,8 +4556,6 @@ snapshots: devlop: 1.1.0 highlight.js: 11.11.1 - lru-cache@11.0.2: {} - lru-cache@11.2.4: {} magic-string@0.30.21: @@ -4954,11 +4947,6 @@ snapshots: path-parse@1.0.7: {} - path-scurry@2.0.0: - dependencies: - lru-cache: 11.0.2 - minipass: 7.1.2 - path-scurry@2.0.1: dependencies: lru-cache: 11.2.4 From 41be1a36b901462e9172aa67e59350c6cb7f157d Mon Sep 17 00:00:00 2001 From: Jared Wray Date: Sat, 13 Dec 2025 10:58:41 -0800 Subject: [PATCH 2/2] moving to pnpm-workspace --- package.json | 7 +------ pnpm-workspace.yaml | 3 +++ 2 files changed, 4 insertions(+), 6 deletions(-) diff --git a/package.json b/package.json index 44d370d..a41028f 100644 --- a/package.json +++ b/package.json @@ -80,10 +80,5 @@ "dist", "public", "LICENCE" - ], - "pnpm": { - "overrides": { - "glob@<=11.1.0": "11.1.0" - } - } + ] } diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml index 735c15a..a1b9c4c 100644 --- a/pnpm-workspace.yaml +++ b/pnpm-workspace.yaml @@ -5,3 +5,6 @@ onlyBuiltDependencies: - esbuild - unrs-resolver - vue-demi + +overrides: + 'glob@<=11.1.0': '11.1.0'