Main (7537de9e7) moved most of the vulnerable locked versions, but some fixes live only in the lockfiles and some advisories stayed open. This commit closes the rest: website/package.json gets durable overrides for js-yaml 4.3.1, dompurify 3.4.13, mermaid 11.16.1, and tar 7.5.22. The root workspace gets the same tar override, which moves the tar 6.2.1 copies under get-windows and @mapbox/node-pre-gyp past twelve open advisories. Without an override, a reinstall can pull an old transitive copy back in. image-size <=2.0.2 has two infinite-loop DoS advisories and no fixed release upstream. An override points it at @nous-research/image-size 2.0.3, our maintained fork of the real repo. The OSV scanner resolves the aliased fork cleanly, so no ignore entries are needed. The photon sidecar moves @opentelemetry/core to 2.10.0. The whatsapp-bridge gets a body-parser 1.20.6 override, so the lockfile-only fix from main cannot regress on reinstall. website/.npmrc gets matching min-release-age exclusions for the fix releases that are less than two weeks old. electron stays at 40.10.2. The 41.x fix for GHSA-9f4c-93c8-jc8g brings back the install failure thatbb8280b75reverted: install.js in 40.10.3+ extracts with an MSVC native binding, which fails on Windows machines without the VC++ Redistributable. Upstream tracks this in electron/electron#52481, with no fix released.
35 lines
1.4 KiB
Plaintext
35 lines
1.4 KiB
Plaintext
# needed to prevent bad npm that has min-release-age but not exclude
|
|
engine-strict=true
|
|
|
|
min-release-age=14
|
|
|
|
# fast-uri 3.1.5 includes fixes for vulns (GHSA-7p8r-x3mc-p8w7). remove this when 3.1.5 is > 2wks old (rel 2026-07-31)
|
|
min-release-age-exclude[]=fast-uri
|
|
|
|
# js-yaml 4.3.1 includes fixes for GHSA-5p4m-2wfm-xmqj. remove when > 2wks old (rel 2026-07-31)
|
|
min-release-age-exclude[]=js-yaml
|
|
|
|
# nanoid 3.3.17 includes fixes for GHSA-2v37-7h3g-55p8. remove when > 2wks old (rel 2026-08-03)
|
|
min-release-age-exclude[]=nanoid
|
|
|
|
# mermaid 11.16.1 includes fixes for 5 GHSAs. remove when > 2wks old (rel 2026-08-04)
|
|
min-release-age-exclude[]=mermaid
|
|
|
|
# dompurify 3.4.13 includes fixes for GHSA-55q2-fjhq-7xh7. remove when > 2wks old (rel 2026-08-03)
|
|
min-release-age-exclude[]=dompurify
|
|
|
|
# minimatch 10.2.6 includes fixes for vulns. remove this when 10.2.6 is > 2wks old
|
|
min-release-age-exclude[]=minimatch
|
|
|
|
# brace-expansion 5.0.8 includes fixes for vulns. remove this when 5.0.8 is > 2wks old
|
|
min-release-age-exclude[]=brace-expansion
|
|
|
|
# postcss 8.5.23 includes fixes for vulns. remove this when 8.5.23 is > 2wks old
|
|
min-release-age-exclude[]=postcss
|
|
|
|
# undici 6.28.0 includes fixes for vulns. remove this when 6.28.0 is > 2wks old
|
|
min-release-age-exclude[]=undici
|
|
|
|
# @nous-research/image-size 2.0.3 includes fixes for vulns. remove this when 2.0.3 is > 2wks old
|
|
min-release-age-exclude[]=@nous-research/image-size
|