Files
warmbly/docs/pnpm-workspace.yaml
T

34 lines
1.5 KiB
YAML

# pnpm 11+ settings live here, not in package.json.
# Trust the install-time native build scripts so `pnpm install` + `next build`
# work without manual approval (adding this file activates pnpm's build gate).
allowBuilds:
esbuild: true
sharp: true
unrs-resolver: true
overrides:
picomatch: ^4.0.4
path-to-regexp: ^8.4.0
# Clear CVE-2026-59869 (DoS via crafted YAML) and GHSA-5p4m-2wfm-xmqj
# (quadratic CPU use resolving !!omap) in the transitive js-yaml.
js-yaml: ^4.3.2
# Clear the libvips CVEs inherited by sharp (fixed in 0.35.0).
sharp: ^0.35.0
# next pins postcss to an exact 8.4.31, which carries the sourceMappingURL
# file-read / path-traversal advisories (CVE-2026-45623, GHSA-r28c-9q8g-f849).
postcss: ^8.5.23
# Clear CVE-2026-67213 (DoS via infinite loop) in the transitive nanoid.
nanoid: ^3.3.17
# Clear GHSA-w3rx-r6r6-pgpr and GHSA-5p2g-fcmc-qvqq in the image-size that
# fumadocs-core pulls in. Build-time only on repo-authored MDX, but the docs
# site is in scope for the dependency scan and an unjustified high finding is
# the same amount of work to explain as to fix.
image-size: ^2.0.3
# Clear GHSA-w9m9-85wc-3x92 (DoS through uncontrolled AST recursion) in the
# postcss-selector-parser fumadocs-ui pulls in.
postcss-selector-parser: '>=7.1.3'
# fumadocs-mdx pins an esbuild carrying GHSA-g7r4-m6w7-qqqr, where the dev
# server serves any file to any origin. Build-time only here, and the docs
# site is a static export, but the fix is a version bump.
esbuild: '>=0.28.1'