Main (7537de9e7) moved most of the vulnerable locked versions, but some fixes live only in the lockfiles and some advisories stayed open. This commit closes the rest: website/package.json gets durable overrides for js-yaml 4.3.1, dompurify 3.4.13, mermaid 11.16.1, and tar 7.5.22. The root workspace gets the same tar override, which moves the tar 6.2.1 copies under get-windows and @mapbox/node-pre-gyp past twelve open advisories. Without an override, a reinstall can pull an old transitive copy back in. image-size <=2.0.2 has two infinite-loop DoS advisories and no fixed release upstream. An override points it at @nous-research/image-size 2.0.3, our maintained fork of the real repo. The OSV scanner resolves the aliased fork cleanly, so no ignore entries are needed. The photon sidecar moves @opentelemetry/core to 2.10.0. The whatsapp-bridge gets a body-parser 1.20.6 override, so the lockfile-only fix from main cannot regress on reinstall. website/.npmrc gets matching min-release-age exclusions for the fix releases that are less than two weeks old. electron stays at 40.10.2. The 41.x fix for GHSA-9f4c-93c8-jc8g brings back the install failure thatbb8280b75reverted: install.js in 40.10.3+ extracts with an MSVC native binding, which fails on Windows machines without the VC++ Redistributable. Upstream tracks this in electron/electron#52481, with no fix released.
21 lines
446 B
JSON
21 lines
446 B
JSON
{
|
|
"name": "hermes-whatsapp-bridge",
|
|
"version": "1.0.0",
|
|
"description": "WhatsApp bridge for Hermes Agent using Baileys",
|
|
"private": true,
|
|
"type": "module",
|
|
"scripts": {
|
|
"start": "node bridge.js"
|
|
},
|
|
"dependencies": {
|
|
"@whiskeysockets/baileys": "7.0.0-rc13",
|
|
"express": "^4.21.0",
|
|
"qrcode-terminal": "^0.12.0",
|
|
"pino": "^9.0.0"
|
|
},
|
|
"overrides": {
|
|
"protobufjs": "^7.5.5",
|
|
"body-parser": "1.20.6"
|
|
}
|
|
}
|