mirror of
https://github.com/supabase/supabase.git
synced 2026-10-10 11:55:05 +03:00
## Summary - Bumps vulnerable transitive dependencies flagged by `pnpm audit`, one commit per dependency (lockfile only, no permanent overrides): proxy-addr, shell-quote, @fastify/busboy, @graphql-tools/executor-legacy-ws, @modelcontextprotocol/sdk, compression, http-cache-semantics, source-map-js, smol-toml, dompurify. - Updates `scripts/fix-audit-vulnerability.ts` to be agent-friendly: accepts a dependency name argument, adds `--json` (single JSON object on stdout, logs on stderr, never prompts) and `--help`. ## Not fixed The remaining audit findings could not be resolved by this script. Some are blocked by `minimumReleaseAge` (braces, node-forge, sprintf-js); others stay vulnerable even with an override and need a parent dependency update or scoped override. ## Test plan - [ ] CI passes (typecheck, lint, prettier) - [ ] `pnpm audit` shows fewer findings than on master 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
34 lines
842 B
JSON
34 lines
842 B
JSON
{
|
|
"name": "@supabase/vue-blocks",
|
|
"version": "0.1.0",
|
|
"private": true,
|
|
"type": "module",
|
|
"exports": "./index.ts",
|
|
"scripts": {
|
|
"preinstall": "npx only-allow pnpm",
|
|
"clean": "rimraf .next .turbo tsconfig.tsbuildinfo",
|
|
"typecheck": "tsc --noEmit"
|
|
},
|
|
"dependencies": {
|
|
"@supabase/postgrest-js": "catalog:",
|
|
"@supabase/ssr": "catalog:",
|
|
"@supabase/supabase-js": "catalog:",
|
|
"@vueuse/core": "^14.1.0",
|
|
"class-variance-authority": "^0.7.1",
|
|
"cn": "catalog:",
|
|
"h3": "^1.15.10",
|
|
"lucide-vue-next": "^0.562.0",
|
|
"nuxt": "^4.4.6",
|
|
"vue": "^3.5.35",
|
|
"vue-router": "^4.5.1"
|
|
},
|
|
"devDependencies": {
|
|
"@types/node": "catalog:",
|
|
"@typescript/native": "catalog:",
|
|
"shadcn": "^4.0.0",
|
|
"tsconfig": "workspace:*",
|
|
"typescript": "catalog:",
|
|
"vite": "^8.0.0"
|
|
}
|
|
}
|