chore: Bump vulnerable dependencies (#44180)

Each dependency was bumped in its commit.
This commit is contained in:
Ivan Vasilov authored and GitHub committed 2026-03-25 14:02:11 +01:00
1 parent a8578384ea
commit e671676696
4 files changed
+2369 -1906

No files matched your search

+26
View File
@@ -258,6 +258,32 @@ async function main(): Promise<void> {
console.error(
`\nNo matching version found for "${selected.module_name}@${selected.overrideVersion}", the minimumReleaseAge option forbids it from installing.`
)
// Extract and display dependency chains that failed due to minimumReleaseAge
const blocks = output.split('ERR_PNPM_NO_MATCHING_VERSION')
for (const block of blocks.slice(1)) {
const versionMatch = block.match(
/No matching version found for (\S+) published by .+?\. Version (\S+) satisfies the specs but was released at (.+)/
)
const chainLines = block
.split('\n')
.filter((line: string) => /^\s+at /.test(line))
.map((line: string) => line.trim().replace(/^at /, ''))
if (versionMatch) {
const [, spec, version, releaseDate] = versionMatch
console.error(`\n Blocked package: ${spec} (v${version} released ${releaseDate.trim()})`)
if (chainLines.length > 0) {
console.error(` Dependency chain: ${chainLines.join(' -> ')}`)
}
// Handle scoped (@org/pkg) and unscoped packages: strip the version range suffix
const pkgName = spec.replace(/@[^/]*$/, '')
console.error(
` To unblock, add "${pkgName}" to the minimumReleaseAgeExclude setting in pnpm-workspace.yaml`
)
}
}
revert()
process.exit(1)
}