mirror of
https://github.com/warmbly/warmbly.git
synced 2026-10-03 08:02:04 +00:00
34 lines
1.5 KiB
YAML
34 lines
1.5 KiB
YAML
# pnpm 11+ settings live here, not in package.json.
|
|
# Trust the install-time native build scripts so `pnpm install` + `next build`
|
|
# work without manual approval (adding this file activates pnpm's build gate).
|
|
allowBuilds:
|
|
esbuild: true
|
|
sharp: true
|
|
unrs-resolver: true
|
|
|
|
overrides:
|
|
picomatch: ^4.0.4
|
|
path-to-regexp: ^8.4.0
|
|
# Clear CVE-2026-59869 (DoS via crafted YAML) and GHSA-5p4m-2wfm-xmqj
|
|
# (quadratic CPU use resolving !!omap) in the transitive js-yaml.
|
|
js-yaml: ^4.3.2
|
|
# Clear the libvips CVEs inherited by sharp (fixed in 0.35.0).
|
|
sharp: ^0.35.0
|
|
# next pins postcss to an exact 8.4.31, which carries the sourceMappingURL
|
|
# file-read / path-traversal advisories (CVE-2026-45623, GHSA-r28c-9q8g-f849).
|
|
postcss: ^8.5.23
|
|
# Clear CVE-2026-67213 (DoS via infinite loop) in the transitive nanoid.
|
|
nanoid: ^3.3.17
|
|
# Clear GHSA-w3rx-r6r6-pgpr and GHSA-5p2g-fcmc-qvqq in the image-size that
|
|
# fumadocs-core pulls in. Build-time only on repo-authored MDX, but the docs
|
|
# site is in scope for the dependency scan and an unjustified high finding is
|
|
# the same amount of work to explain as to fix.
|
|
image-size: ^2.0.3
|
|
# Clear GHSA-w9m9-85wc-3x92 (DoS through uncontrolled AST recursion) in the
|
|
# postcss-selector-parser fumadocs-ui pulls in.
|
|
postcss-selector-parser: '>=7.1.3'
|
|
# fumadocs-mdx pins an esbuild carrying GHSA-g7r4-m6w7-qqqr, where the dev
|
|
# server serves any file to any origin. Build-time only here, and the docs
|
|
# site is a static export, but the fix is a version bump.
|
|
esbuild: '>=0.28.1'
|