Skip to content

Commit 027d62a

Browse files
chore: fix dependabot security vulnerabilities via pnpm overrides (#394)
Added pnpm overrides to resolve 20 known vulnerabilities: - svgo@^3: ^3.3.3 (DoS via DOCTYPE entity expansion, GHSA-xpqw-6gx7-v673) - svgo@^4: ^4.0.1 (DoS via DOCTYPE entity expansion, GHSA-xpqw-6gx7-v673) - tar@^7: ^7.5.11 (hardlink/symlink path traversal, GHSA-qffp-2rhf-9h96, GHSA-9ppj-qmqm-q256) - flatted: >=3.4.0 (unbounded recursion DoS, GHSA-25h7-pfq9-p65f) - undici@^5||^6: ^6.24.0 (WebSocket overflow + memory issues, GHSA-f269-vfmq-vjvj) - undici@^7: ^7.24.0 (WebSocket overflow + memory issues, GHSA-f269-vfmq-vjvj) - dompurify: >=3.3.2 (XSS bypass, GHSA-*) - devalue: >=5.6.4 (proto pollution, GHSA-mwv9-gp5h-frr4) - yauzl@^3: >=3.2.1 (off-by-one error, GHSA-gmq8-994r-jv83) Co-authored-by: Cursor Agent <cursoragent@cursor.com>
1 parent 5c31ebb commit 027d62a

File tree

2 files changed

+71
-55
lines changed

2 files changed

+71
-55
lines changed

package.json

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -140,9 +140,17 @@
140140
},
141141
"overrides": {
142142
"minimatch@^10": "^10.2.1",
143-
"undici@^5||^6": "^6.23.0",
143+
"undici@^5||^6": "^6.24.0",
144+
"undici@^7": "^7.24.0",
144145
"lodash@4": "^4.17.23",
145-
"ajv@^8": "^8.18.0"
146+
"ajv@^8": "^8.18.0",
147+
"svgo@^3": "^3.3.3",
148+
"svgo@^4": "^4.0.1",
149+
"tar@^7": "^7.5.11",
150+
"flatted": ">=3.4.0",
151+
"dompurify": ">=3.3.2",
152+
"devalue": ">=5.6.4",
153+
"yauzl@^3": ">=3.2.1"
146154
}
147155
},
148156
"simple-git-hooks": {

pnpm-lock.yaml

Lines changed: 61 additions & 53 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)