chore: Bump vulnerable dependencies (#44180)

Each dependency was bumped in its commit.
This commit is contained in:
Ivan Vasilov authored and GitHub committed 2026-03-25 14:02:11 +01:00
1 parent a8578384ea
commit e671676696
4 files changed
+2369 -1906

No files matched your search

+2 -2
View File
@@ -15,9 +15,9 @@
"@vueuse/core": "^14.1.0",
"class-variance-authority": "^0.7.1",
"clsx": "^2.1.1",
"h3": "^1.15.5",
"h3": "^1.15.10",
"lucide-vue-next": "^0.562.0",
"nuxt": "^4.0.3",
"nuxt": "^4.4.0",
"tailwind-merge": "^3.3.1",
"vue": "^3.5.21",
"vue-router": "^4.5.1"
+2335 -1887
View File
File diff suppressed because it is too large. Load diff
+6 -17
View File
@@ -23,7 +23,7 @@ catalog:
tsx: 4.20.3
typescript: ~5.9.0
valtio: ^1.12.0
vite: ^7.1.11
vite: ^7.3.1
vitest: ^3.2.0
zod: 3.25.76
@@ -45,24 +45,11 @@ minimumReleaseAgeExclude:
- '@ai-sdk/*'
- '@supabase/*'
- '@supabase-labs/*'
# The following deps were added due to vulnerabilities. You can remove them after the minimum time has passed.
- undici
- next
- '@next/*'
- ai
- js-yaml
- supabase
- iceberg-js
- '@vitejs/plugin-rsc'
- stripe-experiment-sync # TODO(matlin) remove, temp just to unblock launch
- braintrust
- tar
- diff
- lodash-es
- lodash
- next-mdx-remote
- react-resizable-panels
- swiper@12.1.2
- immutable
- undici
- h3
onlyBuiltDependencies:
- node-pty
@@ -76,12 +63,14 @@ overrides:
'@redocly/respect-core>js-yaml': ^4.1.1
'@rollup/plugin-terser>serialize-javascript': ^7.0.3
cacache>tar: ^7.5.11
dompurify: ^3.3.2
esbuild: ^0.25.2
lodash: 'catalog:'
lodash-es: 'catalog:'
node-gyp>tar: ^7.5.11
nodemailer: ^7.0.11
payload>undici: ^7.18.2
'pgsql-parser>libpg-query': ^15.2.0
refractor>prismjs: ^1.30.0
supabase>tar: ^7.5.11
'terser-webpack-plugin>serialize-javascript': ^7.0.3
+26
View File
@@ -258,6 +258,32 @@ async function main(): Promise<void> {
console.error(
`\nNo matching version found for "${selected.module_name}@${selected.overrideVersion}", the minimumReleaseAge option forbids it from installing.`
)
// Extract and display dependency chains that failed due to minimumReleaseAge
const blocks = output.split('ERR_PNPM_NO_MATCHING_VERSION')
for (const block of blocks.slice(1)) {
const versionMatch = block.match(
/No matching version found for (\S+) published by .+?\. Version (\S+) satisfies the specs but was released at (.+)/
)
const chainLines = block
.split('\n')
.filter((line: string) => /^\s+at /.test(line))
.map((line: string) => line.trim().replace(/^at /, ''))
if (versionMatch) {
const [, spec, version, releaseDate] = versionMatch
console.error(`\n Blocked package: ${spec} (v${version} released ${releaseDate.trim()})`)
if (chainLines.length > 0) {
console.error(` Dependency chain: ${chainLines.join(' -> ')}`)
}
// Handle scoped (@org/pkg) and unscoped packages: strip the version range suffix
const pkgName = spec.replace(/@[^/]*$/, '')
console.error(
` To unblock, add "${pkgName}" to the minimumReleaseAgeExclude setting in pnpm-workspace.yaml`
)
}
}
revert()
process.exit(1)
}