Repository navigation
Expand file tree
/
Copy pathpnpm-workspace.yaml
More file actions
187 lines (182 loc) · 11.1 KB
/
Copy pathpnpm-workspace.yaml
File metadata and controls
187 lines (182 loc) · 11.1 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
packages:
- packages/*
- samples/*/*
- samples/integrations/*/*
- tests/*
allowBuilds:
'@parcel/watcher': true
core-js: true
esbuild: true
sharp: true
turbo: true
unrs-resolver: true
overrides:
# JUSTIFICATION: Fixes GHSA-v422-hmwv-36x6 — body-parser silently disables its size limit on an
# invalid `limit` value, allowing a DoS. Transitive via samples/express/quickstart's `express`
# dependency (express > body-parser). express@4's own body-parser range (~1.20.5) already
# permits 1.20.6; remove once a fresh install picks it up without the override.
body-parser: 1.20.6
# JUSTIFICATION: Fixes GHSA-x5fp-wj9c-mxmx (array-limit bypass via bracket-key comma parsing) /
# GHSA-4mjr-xmp4-gh2g (DoS via attacker-controlled isBuffer). Transitive via body-parser's own
# `qs: ~6.15.1` range, which caps at 6.15.3 — the patched 6.15.4 was never published upstream, so
# the fix line jumps straight to 6.16.0. Remove once body-parser bumps its own `qs` range past
# 6.16.0.
body-parser>qs: 6.16.0
# JUSTIFICATION: Fixes GHSA-3jxr-9vmj-r5cp / GHSA-mh99-v99m-4gvg / GHSA-rgw5-rvv9-x895 —
# brace-expansion DoS via exponential/unbounded expansion of `{}` groups — plus GHSA-qhr7-859c-m2p7
# / GHSA-6j4f-fj2g-mc7p (2026-10-02), stack exhaustion via uncontrolled recursion on nested brace
# groups and in `parseCommaParts`, which need >=1.1.20 / >=2.1.6 / >=5.0.11, above the previous
# 1.1.18 / 2.1.4 / 5.0.9 pins. Three major lines are
# pulled in transitively, each needing its own pin: v1 via the root `@thunderid/eslint-plugin`
# toolchain (eslint > minimatch > brace-expansion), v2 via packages/nuxt and packages/vue's
# `@vue/test-utils` (js-beautify > glob > minimatch > brace-expansion), and v5 via the root
# `rimraf` clean scripts (rimraf > glob > minimatch > brace-expansion). Upstream minimatch@latest
# already depends on brace-expansion ^5.0.8, so the v5 pin can likely be dropped on the next
# `pnpm update` once eslint/js-beautify's own lockfile entries catch up too.
brace-expansion@1: 1.1.21
brace-expansion@2: 2.1.7
brace-expansion@5: 5.0.12
# JUSTIFICATION: Fixes GHSA-j22f-vq7h-c4qm / GHSA-mcm9-63f2-9j32 / GHSA-x5rw-q4pp-hg5g — devalue
# `stringify`/`uneval` serializing shared memory, quadratic expansion of repeated primitive
# strings in `uneval`, and an unhandled rejection from `stringifyAsync`. Transitive via
# packages/nuxt and samples/nuxt/quickstart's `nuxt` and `@nuxt/nitro-server`. Added 2026-10-02;
# remove once nuxt's own lockfile entry resolves devalue >=5.9.3 without the override.
devalue: 5.9.4
# JUSTIFICATION: Fixes GHSA-52cp-r559-cp3m / GHSA-5p4m-2wfm-xmqj — js-yaml quadratic CPU
# consumption via YAML merge-key chains and `!!omap` resolution — plus GHSA-2883-xcg3-v3hh
# (2026-09-11), where `maxTotalMergeKeys` fails to bound CPU use for empty merge sources, which
# the previous 4.3.1 pin did not cover. Transitive via the root `eslint` > `@eslint/eslintrc` >
# `js-yaml`. `@eslint/eslintrc`@latest already declares `js-yaml: ^4.3.0`, which permits 4.3.2 —
# this pin can likely be removed once its lockfile entry is refreshed.
js-yaml: 4.3.2
# JUSTIFICATION: Fixes GHSA-28wg-ghj8-5hjv / GHSA-2v37-7h3g-55p8 — nanoid can loop indefinitely
# given a negative or zero size. Two major lines are pulled in: v3 transitively via
# packages/nextjs's `next` > `postcss` > `nanoid` (next still pins `postcss@8.4.31`, which pulls
# an old nanoid — see the `postcss` override below), and v5 via packages/nuxt's
# `@nuxt/devtools` > `@vue/devtools-core` > `nanoid`.
nanoid@3: 3.3.18
nanoid@5: 5.1.16
# JUSTIFICATION: Fixes GHSA-qx2v-qp2m-jg93 (XSS via unescaped `</style>` in stringify output),
# GHSA-6g55-p6wh-862q / GHSA-r28c-9q8g-f849 / GHSA-fxqj-rqcc-2cmp (arbitrary file read via
# attacker-controlled `sourceMappingURL`). Transitive via packages/nextjs and
# samples/nextjs/quickstart's `next` dependency, which still bundles `postcss@8.4.31` internally
# even on the latest 15.5.x release — this is a genuine upstream lag, not a stale lockfile; keep
# the override until Next.js bumps its own postcss pin (https://github.com/vercel/next.js).
postcss: 8.5.23
# JUSTIFICATION: Fixes GHSA-f88m-g3jw-g9cj — sharp inherits several libvips CVEs
# (CVE-2026-33327/33328/35590/35591) — plus GHSA-rgj7-g3m4-5g8c (2026-09-11), which bundles the
# libheif flaws GHSA-g89c-p67h-r497 / GHSA-2jg2-4ch7-h545 and needs >=0.35.4, plus
# GHSA-wq5f-xc86-pv6w (2026-10-06), a librsvg memory flaw that can lead to RCE on glibc-based Linux
# and needs >=0.35.5, above the previous 0.35.4 pin. Transitive via packages/nextjs,
# packages/better-auth and the nextjs samples' `next` > `sharp` (Next.js image optimization).
# `next`@latest already declares `sharp: ^0.35.4`, which permits 0.35.5 — this pin can likely be
# dropped once the lockfile entry is refreshed.
sharp: 0.35.5
# JUSTIFICATION: Fixes GHSA-395f-4hp3-45gv — quadratic-complexity DoS in shell-quote's `parse()`.
# Transitive via packages/nuxt's `@nuxt/devtools` > `launch-editor` > `shell-quote`. Note the
# advisory's own "patched" floor (>=1.8.5) is stale — 1.8.5 was never published; 1.10.0 is the
# first published fix. Also fixes GHSA-pqg4-j6r4-53mv (2026-10-06, critical), `quote()` command
# injection via a line terminator in a token after a `{ comment }` token, which needs >=1.11.0,
# above the previous 1.10.0 pin. `launch-editor`@latest already declares `shell-quote: ^1.10.0`,
# which permits 1.12.0 — this pin can likely be dropped once the lockfile entry is refreshed.
shell-quote: 1.12.0
# JUSTIFICATION: Fixes GHSA-68fv-2mgg-jv7q — source-map-js event-loop DoS through indexed
# source-map section offsets. Transitive via `postcss`, `@vue/compiler-core`, `css-tree` and
# `magicast` across the vitest/vite/nuxt toolchains. Their ranges already permit 1.2.2; the
# lockfile just kept resolving 1.2.1, so this pin can likely be dropped once those entries are
# refreshed. Added 2026-10-06.
source-map-js: 1.2.2
# JUSTIFICATION: Fixes GHSA-2p49-hgcm-8545 — SVGO's `removeScripts` plugin leaves some executable
# script content intact — plus GHSA-w27v-7q3p-w38r (2026-09-11), a follow-up bypass of the same
# plugin via namespaced and control-character-obfuscated links that needs >=4.1.0, above the
# previous 4.0.2 pin. Transitive via packages/nuxt's Vite build pipeline
# (`@nuxt/vite-builder` > `cssnano` > `cssnano-preset-default` > `postcss-svgo` > `svgo`).
# `postcss-svgo`@latest already depends on `svgo: ^4.0.2`, which permits 4.1.0, so this pin can
# likely be dropped once nuxt's own lockfile entry for `postcss-svgo` is refreshed.
svgo: 4.1.0
# JUSTIFICATION: Fixes 5 node-tar advisories (GHSA-w8wr-v893-vjvp, GHSA-23hp-3jrh-7fpw,
# GHSA-8x88-c5mf-7j5w, GHSA-gvwx-54wh-qm9j, GHSA-r292-9mhp-454m) — PAX path/NUL-byte parsing
# crashes, an unbounded-decompression DoS, and a mapHas/filesFilter stack-overflow DoS. Transitive
# via packages/nuxt and samples/nuxt/quickstart's SSR build tooling
# (`nuxt` > `@nuxt/nitro-server` > `nitropack` > `@vercel/nft` > `@mapbox/node-pre-gyp` > `tar`).
# `@mapbox/node-pre-gyp`@latest already depends on `tar: ^7.4.0`, which permits 7.5.21 — this pin
# can likely be dropped once nitropack/@vercel/nft's own lockfile entries are refreshed.
tar: 7.5.21
auditConfig:
ignoreGhsas:
# JUSTIFICATION: GHSA-g7r4-m6w7-qqqr — esbuild's dev server allows arbitrary file reads, but
# only when running on Windows with the dev/serve command exposed on the network; it does not
# affect `vite build`/`vitest run` output. Transitive via `vitest` > `vite` > `esbuild`
# (pulled into every package that runs vitest). The only patched line is 0.28.x, and
# overriding to it breaks samples/vue/quickstart's production build: esbuild 0.28 dropped
# object-destructuring transform support for the sample's configured legacy browser targets
# (chrome87/edge88/firefox78/safari14). Revisit once esbuild backports the fix to 0.27.x or
# the sample's target list is modernized.
- GHSA-g7r4-m6w7-qqqr
# JUSTIFICATION: GHSA-86w9-cpqp-85rv — node-forge accepts extra nested DigestAlgorithm elements
# during RSA PKCS#1 v1.5 signature verification. No patched release exists (1.4.0 is the
# latest and is affected). Transitive via nuxt's dev tooling (`@nuxt/cli` / `nitropack` >
# `listhen` > `node-forge`), which only uses it to generate RSA keys and self-signed
# certificates for the local HTTPS dev server — it never verifies signatures. Added
# 2026-10-02; revisit once node-forge publishes a fixed release.
- GHSA-86w9-cpqp-85rv
# JUSTIFICATION: GHSA-vfj7-8cjw-p6xm — braces stack-exhaustion DoS through deeply nested brace
# patterns. No patched release exists (3.0.3 is the latest and is affected). Transitive via
# nuxt's build tooling (`@nuxt/nitro-server` > `nitropack` > `globby` > `fast-glob` >
# `micromatch` > `braces`), which only expands glob patterns taken from the project's own
# config and filesystem at build time; no untrusted input reaches it at runtime and it is not
# part of the published SDK output. Added 2026-10-06; revisit once braces publishes a fix.
- GHSA-vfj7-8cjw-p6xm
# JUSTIFICATION: GHSA-x6jw-m9v5-85vh / GHSA-g4wm-2vf7-vfgr / GHSA-858h-whjf-mvg5 (simple-git) and
# GHSA-v5rq-49vh-5v5c (`@simple-git/argv-parser`) — simple-git's unsafe-operations guard can be
# bypassed (`trailer.<token>.cmd`, config includes, long-option abbreviations, `VISUAL`), but
# only when untrusted values reach `SimpleGitOptions.config` or the arguments passed to git.
# Transitive via packages/nuxt and samples/nuxt/quickstart's `nuxt` > `@nuxt/devtools` >
# `simple-git`, where devtools (a dev-time tool) only runs `branch()`, `revparse(['--short',
# 'HEAD'])` and `status()` with fixed arguments on the project's own checkout. The patched
# 4.x line cannot be forced with an override: it drops the default export that
# `@nuxt/devtools` imports (`import Git from 'simple-git'`), which breaks the nuxt build, and
# `@nuxt/devtools`@latest (3.4.2) still declares `simple-git: ^3.36.0`. Added 2026-10-06;
# revisit once `@nuxt/devtools` ships a release that supports simple-git >=4.0.1.
- GHSA-x6jw-m9v5-85vh
- GHSA-g4wm-2vf7-vfgr
- GHSA-858h-whjf-mvg5
- GHSA-v5rq-49vh-5v5c
catalog:
'@emotion/css': 11.13.5
'@floating-ui/react': 0.27.12
'@playwright/test': 1.60.0
'@testing-library/react': 16.3.0
'@thunderid/eslint-plugin': 1.0.1
'@thunderid/prettier-config': 1.0.1
'@types/node': 24.7.2
'@types/react': 19.2.14
'@types/react-dom': 19.2.3
'@vitest/browser-playwright': 4.1.11
base64url: 3.0.1
buffer: 6.0.3
core-js: 3.42.0
cross-fetch: 4.1.0
dompurify: 3.4.13
eslint: 9.39.4
fast-sha256: 1.3.0
jose: 6.2.3
jsdom: 27.0.1
memory-cache: 0.2.0
playwright: 1.60.0
prettier: 3.6.2
process: 0.11.10
randombytes: 2.1.0
react: 19.2.3
react-dom: 19.2.3
react-router: 7.18.2
rimraf: 6.1.3
rolldown: 1.0.0-beta.45
secure-random-bytes: 5.0.1
stream-browserify: 3.0.0
tslib: 2.8.1
typescript: 5.9.3
uuid: 11.1.1
vitest: 4.1.11
minimumReleaseAgeExclude:
- '@thunderid/*'