Main (7537de9e7) moved most of the vulnerable locked versions, but some fixes live only in the lockfiles and some advisories stayed open. This commit closes the rest: website/package.json gets durable overrides for js-yaml 4.3.1, dompurify 3.4.13, mermaid 11.16.1, and tar 7.5.22. The root workspace gets the same tar override, which moves the tar 6.2.1 copies under get-windows and @mapbox/node-pre-gyp past twelve open advisories. Without an override, a reinstall can pull an old transitive copy back in. image-size <=2.0.2 has two infinite-loop DoS advisories and no fixed release upstream. An override points it at @nous-research/image-size 2.0.3, our maintained fork of the real repo. The OSV scanner resolves the aliased fork cleanly, so no ignore entries are needed. The photon sidecar moves @opentelemetry/core to 2.10.0. The whatsapp-bridge gets a body-parser 1.20.6 override, so the lockfile-only fix from main cannot regress on reinstall. website/.npmrc gets matching min-release-age exclusions for the fix releases that are less than two weeks old. electron stays at 40.10.2. The 41.x fix for GHSA-9f4c-93c8-jc8g brings back the install failure thatbb8280b75reverted: install.js in 40.10.3+ extracts with an MSVC native binding, which fails on Windows machines without the VC++ Redistributable. Upstream tracks this in electron/electron#52481, with no fix released.
70 lines
1.8 KiB
JSON
70 lines
1.8 KiB
JSON
{
|
|
"name": "website",
|
|
"version": "0.0.0",
|
|
"private": true,
|
|
"scripts": {
|
|
"docusaurus": "docusaurus",
|
|
"prestart": "node scripts/prebuild.mjs",
|
|
"start": "docusaurus start",
|
|
"prebuild": "node scripts/prebuild.mjs",
|
|
"build": "docusaurus build",
|
|
"build:fast": "docusaurus build --locale en",
|
|
"swizzle": "docusaurus swizzle",
|
|
"deploy": "docusaurus deploy",
|
|
"clear": "docusaurus clear",
|
|
"serve": "docusaurus serve",
|
|
"write-translations": "docusaurus write-translations",
|
|
"write-heading-ids": "docusaurus write-heading-ids",
|
|
"typecheck": "tsc -p . --noEmit",
|
|
"lint:diagrams": "ascii-guard lint --exclude-code-blocks docs"
|
|
},
|
|
"dependencies": {
|
|
"@docusaurus/core": "3.10.2",
|
|
"@docusaurus/plugin-client-redirects": "3.10.2",
|
|
"@docusaurus/preset-classic": "3.10.2",
|
|
"@docusaurus/theme-mermaid": "3.10.2",
|
|
"@mdx-js/react": "3.1.1",
|
|
"clsx": "2.1.1",
|
|
"prism-react-renderer": "2.3.0",
|
|
"react": "19.2.7",
|
|
"react-dom": "19.2.7"
|
|
},
|
|
"devDependencies": {
|
|
"@docusaurus/module-type-aliases": "3.10.2",
|
|
"@docusaurus/tsconfig": "3.10.2",
|
|
"@docusaurus/types": "3.10.2",
|
|
"typescript": "6.0.3"
|
|
},
|
|
"overrides": {
|
|
"serialize-javascript": "7.0.7",
|
|
"uuid": "14.0.1",
|
|
"minimatch": "10.2.6",
|
|
"nanoid": "3.3.17",
|
|
"js-yaml": "4.3.1",
|
|
"dompurify": "3.4.13",
|
|
"mermaid": "11.16.1",
|
|
"image-size": "npm:@nous-research/image-size@2.0.3",
|
|
"tar": "7.5.22"
|
|
},
|
|
"browserslist": {
|
|
"production": [
|
|
">0.5%",
|
|
"not dead",
|
|
"not op_mini all"
|
|
],
|
|
"development": [
|
|
"last 3 chrome version",
|
|
"last 3 firefox version",
|
|
"last 5 safari version"
|
|
]
|
|
},
|
|
"engines": {
|
|
"node": ">=20.0",
|
|
"npm": ">=11.17.0"
|
|
},
|
|
"allowScripts": {
|
|
"core-js@3.49.0": true,
|
|
"fsevents@2.3.3": true
|
|
}
|
|
}
|