mirror of
https://github.com/supabase/supabase.git
synced 2026-10-08 10:55:06 +03:00
## Summary - Bumps vulnerable transitive dependencies flagged by `pnpm audit`, one commit per dependency (lockfile only, no permanent overrides): proxy-addr, shell-quote, @fastify/busboy, @graphql-tools/executor-legacy-ws, @modelcontextprotocol/sdk, compression, http-cache-semantics, source-map-js, smol-toml, dompurify. - Updates `scripts/fix-audit-vulnerability.ts` to be agent-friendly: accepts a dependency name argument, adds `--json` (single JSON object on stdout, logs on stderr, never prompts) and `--help`. ## Not fixed The remaining audit findings could not be resolved by this script. Some are blocked by `minimumReleaseAge` (braces, node-forge, sprintf-js); others stay vulnerable even with an override and need a parent dependency update or scoped override. ## Test plan - [ ] CI passes (typecheck, lint, prettier) - [ ] `pnpm audit` shows fewer findings than on master 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
113 lines
3.9 KiB
JSON
113 lines
3.9 KiB
JSON
{
|
|
"name": "library",
|
|
"version": "0.1.0",
|
|
"private": true,
|
|
"type": "module",
|
|
"scripts": {
|
|
"preinstall": "npx only-allow pnpm",
|
|
"dev:content": "velite dev",
|
|
"dev:next": "next dev --port 3004",
|
|
"dev": "pnpm build:registry && run-p build:content build:markdown build:markdown-index && run-p --race dev:*",
|
|
"build:content": "velite build --strict",
|
|
"build:registry": "rimraf -G public/r/* && tsx ./scripts/build-registry.mts && shadcn build public/r/registry.json && tsx scripts/clean-registry.ts",
|
|
"build:markdown": "tsx ./scripts/build-markdown.ts",
|
|
"build:markdown-index": "tsx ./scripts/build-markdown-index.ts",
|
|
"build:next": "next build --turbopack",
|
|
"build": "pnpm build:registry && run-p build:content build:markdown build:markdown-index && pnpm build:next",
|
|
"test": "pnpm build:markdown && vitest",
|
|
"test:headless-tools": "tsx scripts/test-headless-tools.mts",
|
|
"start": "next start",
|
|
"lint": "eslint .",
|
|
"lint:ratchet": "tsx node_modules/eslint-config-supabase/ratchet-eslint-rules.ts --rules-file node_modules/eslint-config-supabase/ratchet-rules.json",
|
|
"clean": "rimraf .next .turbo tsconfig.tsbuildinfo .contentlayer .velite",
|
|
"typecheck": "run-p build:content build:markdown && next typegen && tsc --noEmit -p tsconfig.json"
|
|
},
|
|
"dependencies": {
|
|
"@hookform/resolvers": "^3.1.1",
|
|
"@monaco-editor/react": "catalog:",
|
|
"@supabase-labs/y-supabase": "0.1.0",
|
|
"@supabase/postgrest-js": "catalog:",
|
|
"@supabase/vue-blocks": "workspace:*",
|
|
"@tanstack/react-query": "~5.83.0",
|
|
"@xyflow/react": "^12.10.1",
|
|
"api-types": "workspace:*",
|
|
"axios": "^1.20.0",
|
|
"class-variance-authority": "^0.7.1",
|
|
"cmdk": "^1.1.1",
|
|
"common": "workspace:*",
|
|
"common-tags": "^1.8.2",
|
|
"eslint-config-supabase": "workspace:*",
|
|
"framer-motion": "^11.18.2",
|
|
"icons": "workspace:*",
|
|
"jotai": "^2.8.0",
|
|
"lucide-react": "*",
|
|
"monaco-editor": "catalog:",
|
|
"next": "catalog:",
|
|
"next-themes": "catalog:",
|
|
"openai": "^5.9.0",
|
|
"openapi-fetch": "0.12.4",
|
|
"radix-ui": "catalog:",
|
|
"react": "catalog:",
|
|
"react-dom": "catalog:",
|
|
"react-hook-form": "^7.71.2",
|
|
"react-markdown": "^10.1.0",
|
|
"react-wrap-balancer": "^1.1.0",
|
|
"recharts": "catalog:",
|
|
"rehype-autolink-headings": "^7.1.0",
|
|
"rehype-pretty-code": "^0.9.0",
|
|
"rehype-slug": "^6.0.0",
|
|
"remark-code-import": "^1.2.0",
|
|
"remark-gfm": "^4.0.0",
|
|
"sonner": "^1.5.0",
|
|
"ui": "workspace:*",
|
|
"ui-patterns": "workspace:*",
|
|
"unist-util-visit": "^5.0.0",
|
|
"vaul": "^1.1.2",
|
|
"velite": "catalog:",
|
|
"y-monaco": "^0.1.6",
|
|
"y-protocols": "^1.0.7",
|
|
"yjs": "^13.6.29",
|
|
"zod": "catalog:"
|
|
},
|
|
"devDependencies": {
|
|
"@babel/core": "*",
|
|
"@react-router/dev": "^7.17.1",
|
|
"@react-router/fs-routes": "^7.18.4",
|
|
"@shikijs/compat": "^1.1.7",
|
|
"@supabase/ssr": "catalog:",
|
|
"@supabase/supabase-js": "catalog:",
|
|
"@tanstack/react-router": "catalog:",
|
|
"@tanstack/react-start": "catalog:",
|
|
"@types/common-tags": "^1.8.4",
|
|
"@types/lodash": "^4.17.16",
|
|
"@types/node": "catalog:",
|
|
"@types/mdast": "^3.0.15",
|
|
"@types/react": "catalog:",
|
|
"@types/react-dom": "catalog:",
|
|
"@typescript/native": "catalog:",
|
|
"config": "workspace:^",
|
|
"gray-matter": "^4.0.3",
|
|
"lodash": "catalog:",
|
|
"mdast-util-from-markdown": "^1.3.1",
|
|
"mdast-util-gfm": "^2.0.2",
|
|
"mdast-util-mdx": "^2.0.1",
|
|
"mdast-util-mdx-jsx": "^2.1.4",
|
|
"mdast-util-to-markdown": "^1.5.0",
|
|
"micromark-extension-gfm": "^2.0.3",
|
|
"micromark-extension-mdxjs": "^1.0.1",
|
|
"npm-run-all": "^4.1.5",
|
|
"postcss": "catalog:",
|
|
"react-dropzone": "^14.3.8",
|
|
"react-router": "^7.13.2",
|
|
"rimraf": "^4.1.3",
|
|
"shadcn": "^4.0.0",
|
|
"shiki": "^1.1.7",
|
|
"tailwindcss": "catalog:",
|
|
"tsconfig": "workspace:*",
|
|
"tsx": "catalog:",
|
|
"typescript": "catalog:",
|
|
"vite": "catalog:",
|
|
"vitest": "catalog:"
|
|
}
|
|
}
|