mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 09:25:06 +03:00
chore: Bump vulnerable dependencies (#44180)
Each dependency was bumped in its commit.
This commit is contained in:
1 parent
a8578384ea
commit
e671676696
4 files changed
+2369
-1906
No files matched your search
@@ -15,9 +15,9 @@
|
||||
"@vueuse/core": "^14.1.0",
|
||||
"class-variance-authority": "^0.7.1",
|
||||
"clsx": "^2.1.1",
|
||||
"h3": "^1.15.5",
|
||||
"h3": "^1.15.10",
|
||||
"lucide-vue-next": "^0.562.0",
|
||||
"nuxt": "^4.0.3",
|
||||
"nuxt": "^4.4.0",
|
||||
"tailwind-merge": "^3.3.1",
|
||||
"vue": "^3.5.21",
|
||||
"vue-router": "^4.5.1"
|
||||
|
||||
Generated
+2335
-1887
File diff suppressed because it is too large.
Load diff
+6
-17
@@ -23,7 +23,7 @@ catalog:
|
||||
tsx: 4.20.3
|
||||
typescript: ~5.9.0
|
||||
valtio: ^1.12.0
|
||||
vite: ^7.1.11
|
||||
vite: ^7.3.1
|
||||
vitest: ^3.2.0
|
||||
zod: 3.25.76
|
||||
|
||||
@@ -45,24 +45,11 @@ minimumReleaseAgeExclude:
|
||||
- '@ai-sdk/*'
|
||||
- '@supabase/*'
|
||||
- '@supabase-labs/*'
|
||||
# The following deps were added due to vulnerabilities. You can remove them after the minimum time has passed.
|
||||
- undici
|
||||
- next
|
||||
- '@next/*'
|
||||
- ai
|
||||
- js-yaml
|
||||
- supabase
|
||||
- iceberg-js
|
||||
- '@vitejs/plugin-rsc'
|
||||
- stripe-experiment-sync # TODO(matlin) remove, temp just to unblock launch
|
||||
- braintrust
|
||||
- tar
|
||||
- diff
|
||||
- lodash-es
|
||||
- lodash
|
||||
- next-mdx-remote
|
||||
- react-resizable-panels
|
||||
- swiper@12.1.2
|
||||
- immutable
|
||||
- undici
|
||||
- h3
|
||||
|
||||
onlyBuiltDependencies:
|
||||
- node-pty
|
||||
@@ -76,12 +63,14 @@ overrides:
|
||||
'@redocly/respect-core>js-yaml': ^4.1.1
|
||||
'@rollup/plugin-terser>serialize-javascript': ^7.0.3
|
||||
cacache>tar: ^7.5.11
|
||||
dompurify: ^3.3.2
|
||||
esbuild: ^0.25.2
|
||||
lodash: 'catalog:'
|
||||
lodash-es: 'catalog:'
|
||||
node-gyp>tar: ^7.5.11
|
||||
nodemailer: ^7.0.11
|
||||
payload>undici: ^7.18.2
|
||||
'pgsql-parser>libpg-query': ^15.2.0
|
||||
refractor>prismjs: ^1.30.0
|
||||
supabase>tar: ^7.5.11
|
||||
'terser-webpack-plugin>serialize-javascript': ^7.0.3
|
||||
|
||||
@@ -258,6 +258,32 @@ async function main(): Promise<void> {
|
||||
console.error(
|
||||
`\nNo matching version found for "${selected.module_name}@${selected.overrideVersion}", the minimumReleaseAge option forbids it from installing.`
|
||||
)
|
||||
|
||||
// Extract and display dependency chains that failed due to minimumReleaseAge
|
||||
const blocks = output.split('ERR_PNPM_NO_MATCHING_VERSION')
|
||||
for (const block of blocks.slice(1)) {
|
||||
const versionMatch = block.match(
|
||||
/No matching version found for (\S+) published by .+?\. Version (\S+) satisfies the specs but was released at (.+)/
|
||||
)
|
||||
const chainLines = block
|
||||
.split('\n')
|
||||
.filter((line: string) => /^\s+at /.test(line))
|
||||
.map((line: string) => line.trim().replace(/^at /, ''))
|
||||
|
||||
if (versionMatch) {
|
||||
const [, spec, version, releaseDate] = versionMatch
|
||||
console.error(`\n Blocked package: ${spec} (v${version} released ${releaseDate.trim()})`)
|
||||
if (chainLines.length > 0) {
|
||||
console.error(` Dependency chain: ${chainLines.join(' -> ')}`)
|
||||
}
|
||||
// Handle scoped (@org/pkg) and unscoped packages: strip the version range suffix
|
||||
const pkgName = spec.replace(/@[^/]*$/, '')
|
||||
console.error(
|
||||
` To unblock, add "${pkgName}" to the minimumReleaseAgeExclude setting in pnpm-workspace.yaml`
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
revert()
|
||||
process.exit(1)
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user