Skip to content

Commit c488280

Browse files
chore(deps): bump vulnerable transitive dependencies via resolutions
Add yarn resolutions to upgrade path-to-regexp (^8.4.0), picomatch v4 (^4.0.4), and fast-xml-parser (^5.5.6) to patched versions. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
1 parent 14143e2 commit c488280

File tree

2 files changed

+135
-30
lines changed

2 files changed

+135
-30
lines changed

package.json

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,9 @@
3737
"node-gyp/glob": "^10.5.0",
3838
"sucrase/glob": "^10.5.0",
3939
"rimraf@npm:5.0.10/glob": "^10.5.0",
40-
"@opentelemetry/resources": "2.5.1"
40+
"@opentelemetry/resources": "2.5.1",
41+
"path-to-regexp": "^8.4.0",
42+
"picomatch@^4": "^4.0.4",
43+
"fast-xml-parser": "^5.5.6"
4144
}
4245
}

yarn.lock

Lines changed: 131 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -3838,7 +3838,7 @@ __metadata:
38383838
languageName: node
38393839
linkType: hard
38403840

3841-
"@modelcontextprotocol/sdk@npm:^1.25.0, @modelcontextprotocol/sdk@npm:^1.26.0, @modelcontextprotocol/sdk@npm:^1.27.1":
3841+
"@modelcontextprotocol/sdk@npm:^1.25.0, @modelcontextprotocol/sdk@npm:^1.26.0":
38423842
version: 1.27.1
38433843
resolution: "@modelcontextprotocol/sdk@npm:1.27.1"
38443844
dependencies:
@@ -3871,6 +3871,39 @@ __metadata:
38713871
languageName: node
38723872
linkType: hard
38733873

3874+
"@modelcontextprotocol/sdk@npm:^1.27.1":
3875+
version: 1.29.0
3876+
resolution: "@modelcontextprotocol/sdk@npm:1.29.0"
3877+
dependencies:
3878+
"@hono/node-server": "npm:^1.19.9"
3879+
ajv: "npm:^8.17.1"
3880+
ajv-formats: "npm:^3.0.1"
3881+
content-type: "npm:^1.0.5"
3882+
cors: "npm:^2.8.5"
3883+
cross-spawn: "npm:^7.0.5"
3884+
eventsource: "npm:^3.0.2"
3885+
eventsource-parser: "npm:^3.0.0"
3886+
express: "npm:^5.2.1"
3887+
express-rate-limit: "npm:^8.2.1"
3888+
hono: "npm:^4.11.4"
3889+
jose: "npm:^6.1.3"
3890+
json-schema-typed: "npm:^8.0.2"
3891+
pkce-challenge: "npm:^5.0.0"
3892+
raw-body: "npm:^3.0.0"
3893+
zod: "npm:^3.25 || ^4.0"
3894+
zod-to-json-schema: "npm:^3.25.1"
3895+
peerDependencies:
3896+
"@cfworker/json-schema": ^4.1.1
3897+
zod: ^3.25 || ^4.0
3898+
peerDependenciesMeta:
3899+
"@cfworker/json-schema":
3900+
optional: true
3901+
zod:
3902+
optional: false
3903+
checksum: 10c0/7c4bc339205b1652330cd4e6b121cc859079655f2b9c0506bbb15563ba0d07924bda3d949705530532db7f4d2cb86d633dc8f92bc32803d97c7bece2ac63e29f
3904+
languageName: node
3905+
linkType: hard
3906+
38743907
"@msgpack/msgpack@npm:^2.5.1":
38753908
version: 2.8.0
38763909
resolution: "@msgpack/msgpack@npm:2.8.0"
@@ -7350,17 +7383,35 @@ __metadata:
73507383
languageName: node
73517384
linkType: hard
73527385

7386+
"@react-grab/cli@npm:0.1.29":
7387+
version: 0.1.29
7388+
resolution: "@react-grab/cli@npm:0.1.29"
7389+
dependencies:
7390+
"@antfu/ni": "npm:^0.23.0"
7391+
commander: "npm:^14.0.0"
7392+
ignore: "npm:^7.0.5"
7393+
jsonc-parser: "npm:^3.3.1"
7394+
ora: "npm:^8.2.0"
7395+
picocolors: "npm:^1.1.1"
7396+
prompts: "npm:^2.4.2"
7397+
smol-toml: "npm:^1.6.0"
7398+
bin:
7399+
react-grab: dist/cli.js
7400+
checksum: 10c0/b67c6ea6f14f722cf066629ed01b0fe9a0dd893c0c7a9c525b8b2c39503dc6d3defa339ddcb0fec8a3ea79e92ea933a70c2fa82580d2da3e7eba382ef9710cb2
7401+
languageName: node
7402+
linkType: hard
7403+
73537404
"@react-grab/mcp@npm:^0.1.23":
7354-
version: 0.1.23
7355-
resolution: "@react-grab/mcp@npm:0.1.23"
7405+
version: 0.1.29
7406+
resolution: "@react-grab/mcp@npm:0.1.29"
73567407
dependencies:
73577408
"@modelcontextprotocol/sdk": "npm:^1.25.0"
73587409
fkill: "npm:^9.0.0"
7359-
react-grab: "npm:0.1.23"
7410+
react-grab: "npm:0.1.29"
73607411
zod: "npm:^3.25.0"
73617412
bin:
73627413
react-grab-mcp: dist/cli.cjs
7363-
checksum: 10c0/0c0eac7081138b2b55a1171607371c8918139d8f249908bc3e57ae9cc1e92c5d5e9ca8b14c7bb20da4ad5be2ab7c2029179b5248f7d10e88edc229acbdf809ae
7414+
checksum: 10c0/ce852f1eac43a7b932ad494f8b76f2cd9ec654fe64e8c9ea950ee1739af9fb636c20792623322ca772fac2858b735cd17f49cf4aa59b9311b4a75843fd9657b6
73647415
languageName: node
73657416
linkType: hard
73667417

@@ -11093,6 +11144,17 @@ __metadata:
1109311144
languageName: node
1109411145
linkType: hard
1109511146

11147+
"bippy@npm:^0.5.32":
11148+
version: 0.5.32
11149+
resolution: "bippy@npm:0.5.32"
11150+
dependencies:
11151+
"@types/react-reconciler": "npm:^0.28.9"
11152+
peerDependencies:
11153+
react: ">=17.0.1"
11154+
checksum: 10c0/019a6800ad54da471ff915a4b5815baa8981ebde1695aca79387fa67cd298d875631b3b83123c05dd2977077bfe0af651b1df59683a78dd428fccd8f80f38894
11155+
languageName: node
11156+
linkType: hard
11157+
1109611158
"body-parser@npm:1.20.3":
1109711159
version: 1.20.3
1109811160
resolution: "body-parser@npm:1.20.3"
@@ -12765,6 +12827,15 @@ __metadata:
1276512827
languageName: node
1276612828
linkType: hard
1276712829

12830+
"element-source@npm:^0.0.3":
12831+
version: 0.0.3
12832+
resolution: "element-source@npm:0.0.3"
12833+
dependencies:
12834+
bippy: "npm:^0.5.32"
12835+
checksum: 10c0/82ff07d9e9a5de3c8a881d6b9a359b3e1e7c9be74657a1dfe9dc8ed2418599b3877534e1a1afc078a3de59a6a7286251a56e2c06d31d951b57642ab8277bdd32
12836+
languageName: node
12837+
linkType: hard
12838+
1276812839
"embla-carousel-auto-scroll@npm:^8.3.0":
1276912840
version: 8.5.2
1277012841
resolution: "embla-carousel-auto-scroll@npm:8.5.2"
@@ -14201,14 +14272,25 @@ __metadata:
1420114272
languageName: node
1420214273
linkType: hard
1420314274

14204-
"fast-xml-parser@npm:5.3.6":
14205-
version: 5.3.6
14206-
resolution: "fast-xml-parser@npm:5.3.6"
14275+
"fast-xml-builder@npm:^1.1.4":
14276+
version: 1.1.4
14277+
resolution: "fast-xml-builder@npm:1.1.4"
1420714278
dependencies:
14208-
strnum: "npm:^2.1.2"
14279+
path-expression-matcher: "npm:^1.1.3"
14280+
checksum: 10c0/d5dfc0660f7f886b9f42747e6aa1d5e16c090c804b322652f65a5d7ffb93aa00153c3e1276cd053629f9f4c4f625131dc6886677394f7048e827e63b97b18927
14281+
languageName: node
14282+
linkType: hard
14283+
14284+
"fast-xml-parser@npm:^5.5.6":
14285+
version: 5.5.9
14286+
resolution: "fast-xml-parser@npm:5.5.9"
14287+
dependencies:
14288+
fast-xml-builder: "npm:^1.1.4"
14289+
path-expression-matcher: "npm:^1.2.0"
14290+
strnum: "npm:^2.2.2"
1420914291
bin:
1421014292
fxparser: src/cli/cli.js
14211-
checksum: 10c0/0150cc0566f327a76115de8b11628d717fb179010ed9bb77c52e579a7e6055a0f92f42f83678a6f1ec5b74411faec09713cb1f9b94bc687068ad86884a9199fa
14293+
checksum: 10c0/b7f40f586c01a916a75be15b11ec0e83a38483885395bdeca51da8992a75e3d4d9b6c2690f362b975bfcb5118909ee4b0393e18ec9c9151345d5e13152370969
1421214294
languageName: node
1421314295
linkType: hard
1421414296

@@ -18505,6 +18587,13 @@ __metadata:
1850518587
languageName: node
1850618588
linkType: hard
1850718589

18590+
"path-expression-matcher@npm:^1.1.3, path-expression-matcher@npm:^1.2.0":
18591+
version: 1.2.0
18592+
resolution: "path-expression-matcher@npm:1.2.0"
18593+
checksum: 10c0/86c661dfb265ed5dd1ddd9188f0dfbecf4ec4dc3ea6cabab081d3a2ba285054d9767a641a233bd6fd694fd89f7d0ef94913032feddf5365252700b02db4bf4e1
18594+
languageName: node
18595+
linkType: hard
18596+
1850818597
"path-key@npm:^2.0.1":
1850918598
version: 2.0.1
1851018599
resolution: "path-key@npm:2.0.1"
@@ -18563,17 +18652,10 @@ __metadata:
1856318652
languageName: node
1856418653
linkType: hard
1856518654

18566-
"path-to-regexp@npm:0.1.12":
18567-
version: 0.1.12
18568-
resolution: "path-to-regexp@npm:0.1.12"
18569-
checksum: 10c0/1c6ff10ca169b773f3bba943bbc6a07182e332464704572962d277b900aeee81ac6aa5d060ff9e01149636c30b1f63af6e69dd7786ba6e0ddb39d4dee1f0645b
18570-
languageName: node
18571-
linkType: hard
18572-
18573-
"path-to-regexp@npm:^8.0.0":
18574-
version: 8.2.0
18575-
resolution: "path-to-regexp@npm:8.2.0"
18576-
checksum: 10c0/ef7d0a887b603c0a142fad16ccebdcdc42910f0b14830517c724466ad676107476bba2fe9fffd28fd4c141391ccd42ea426f32bb44c2c82ecaefe10c37b90f5a
18655+
"path-to-regexp@npm:^8.4.0":
18656+
version: 8.4.2
18657+
resolution: "path-to-regexp@npm:8.4.2"
18658+
checksum: 10c0/05b115c49b47ad252ce05faa32930f643f23769c68b8bcfe78ad833545140c48bbffb3266986d6c8d5db13a64cf12e07e0d72d9882cab830efeefa553533ebaf
1857718659
languageName: node
1857818660
linkType: hard
1857918661

@@ -18694,9 +18776,9 @@ __metadata:
1869418776
linkType: hard
1869518777

1869618778
"picomatch@npm:^4.0.2, picomatch@npm:^4.0.3":
18697-
version: 4.0.3
18698-
resolution: "picomatch@npm:4.0.3"
18699-
checksum: 10c0/9582c951e95eebee5434f59e426cddd228a7b97a0161a375aed4be244bd3fe8e3a31b846808ea14ef2c8a2527a6eeab7b3946a67d5979e81694654f939473ae2
18779+
version: 4.0.4
18780+
resolution: "picomatch@npm:4.0.4"
18781+
checksum: 10c0/e2c6023372cc7b5764719a5ffb9da0f8e781212fa7ca4bd0562db929df8e117460f00dff3cb7509dacfc06b86de924b247f504d0ce1806a37fac4633081466b0
1870018782
languageName: node
1870118783
linkType: hard
1870218784

@@ -19386,7 +19468,27 @@ __metadata:
1938619468
languageName: node
1938719469
linkType: hard
1938819470

19389-
"react-grab@npm:0.1.23, react-grab@npm:^0.1.23":
19471+
"react-grab@npm:0.1.29":
19472+
version: 0.1.29
19473+
resolution: "react-grab@npm:0.1.29"
19474+
dependencies:
19475+
"@medv/finder": "npm:^4.0.2"
19476+
"@react-grab/cli": "npm:0.1.29"
19477+
bippy: "npm:^0.5.32"
19478+
element-source: "npm:^0.0.3"
19479+
solid-js: "npm:^1.9.10"
19480+
peerDependencies:
19481+
react: ">=17.0.0"
19482+
peerDependenciesMeta:
19483+
react:
19484+
optional: true
19485+
bin:
19486+
react-grab: bin/cli.js
19487+
checksum: 10c0/7afd3959f3395c357dbaa5a09a4ce7b7b64455c2b5ed9aac97c84a07e0370af68a31b32b3a43d1724714065cb3f4e1a0f48a9bdb25757fbf86e8ac8baf08c6d7
19488+
languageName: node
19489+
linkType: hard
19490+
19491+
"react-grab@npm:^0.1.23":
1939019492
version: 0.1.23
1939119493
resolution: "react-grab@npm:0.1.23"
1939219494
dependencies:
@@ -21339,10 +21441,10 @@ __metadata:
2133921441
languageName: node
2134021442
linkType: hard
2134121443

21342-
"strnum@npm:^2.1.2":
21343-
version: 2.1.2
21344-
resolution: "strnum@npm:2.1.2"
21345-
checksum: 10c0/4e04753b793540d79cd13b2c3e59e298440477bae2b853ab78d548138385193b37d766d95b63b7046475d68d44fb1fca692f0a3f72b03f4168af076c7b246df9
21444+
"strnum@npm:^2.2.2":
21445+
version: 2.2.2
21446+
resolution: "strnum@npm:2.2.2"
21447+
checksum: 10c0/89c456de32b9495ae34cd6e3b59cb9ef3406b66d1429bbc931afd70be87485dcd355200c42fd638a132adb3121762542346813098ab0c43e44aac303bf17965d
2134621448
languageName: node
2134721449
linkType: hard
2134821450

0 commit comments

Comments
 (0)