Commit 027d62a
chore: fix dependabot security vulnerabilities via pnpm overrides (#394)
Added pnpm overrides to resolve 20 known vulnerabilities:
- svgo@^3: ^3.3.3 (DoS via DOCTYPE entity expansion, GHSA-xpqw-6gx7-v673)
- svgo@^4: ^4.0.1 (DoS via DOCTYPE entity expansion, GHSA-xpqw-6gx7-v673)
- tar@^7: ^7.5.11 (hardlink/symlink path traversal, GHSA-qffp-2rhf-9h96, GHSA-9ppj-qmqm-q256)
- flatted: >=3.4.0 (unbounded recursion DoS, GHSA-25h7-pfq9-p65f)
- undici@^5||^6: ^6.24.0 (WebSocket overflow + memory issues, GHSA-f269-vfmq-vjvj)
- undici@^7: ^7.24.0 (WebSocket overflow + memory issues, GHSA-f269-vfmq-vjvj)
- dompurify: >=3.3.2 (XSS bypass, GHSA-*)
- devalue: >=5.6.4 (proto pollution, GHSA-mwv9-gp5h-frr4)
- yauzl@^3: >=3.2.1 (off-by-one error, GHSA-gmq8-994r-jv83)
Co-authored-by: Cursor Agent <cursoragent@cursor.com>1 parent 5c31ebb commit 027d62a
2 files changed
+71
-55
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
140 | 140 | | |
141 | 141 | | |
142 | 142 | | |
143 | | - | |
| 143 | + | |
| 144 | + | |
144 | 145 | | |
145 | | - | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
146 | 154 | | |
147 | 155 | | |
148 | 156 | | |
| |||
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments