Skip to content

Commit ceb2ea3

Browse files
committed
fix(deps): resolve security vulnerabilities in transitive dependencies
Add pnpm overrides to patch vulnerable dev dependencies: - lodash: 4.17.21 → 4.17.23 (prototype pollution in _.unset/_.omit) - undici: 6.21.3 → 6.23.0 (unbounded decompression chain DoS) - glob: 10.4.5 → 10.5.0 (command injection via -c/--cmd) Also updates direct dev dependencies: - @biomejs/biome: 2.2.5 → 2.3.8 - nano-staged: 0.8.0 → 0.9.0 - release-it: 19.0.5 → 19.1.0 Resolves GitHub Dependabot alerts #23, #24, #25.
1 parent 8679c6e commit ceb2ea3

2 files changed

Lines changed: 24 additions & 12 deletions

File tree

package.json

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -114,5 +114,12 @@
114114
"simple-git-hooks": {
115115
"pre-commit": "pnpm exec nano-staged"
116116
},
117+
"pnpm": {
118+
"overrides": {
119+
"lodash": "^4.17.23",
120+
"undici": "^6.23.0",
121+
"glob": "^10.5.0"
122+
}
123+
},
117124
"packageManager": "pnpm@10.15.0+sha512.486ebc259d3e999a4e8691ce03b5cac4a71cbeca39372a9b762cb500cfdf0873e2cb16abe3d951b1ee2cf012503f027b98b6584e4df22524e0c7450d9ec7aa7b"
118125
}

pnpm-lock.yaml

Lines changed: 17 additions & 12 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)