Repository navigation
Expand file tree
/
Copy pathpnpm-workspace.yaml
More file actions
80 lines (77 loc) · 6.55 KB
/
Copy pathpnpm-workspace.yaml
File metadata and controls
80 lines (77 loc) · 6.55 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
overrides:
# GHSA-7m2j-8qp9-m8jw: CRLF injection. Remove when no transitive dependency uses form-data >=4.0.0 <4.0.6.
"form-data@>=4.0.0 <4.0.6": "4.0.6"
# GHSA-88fw-hqm2-52qc: CORS middleware reflects any origin with credentials. Remove when hono >=4.12.25.
# GHSA-xgm2-5f3f-mvvc / GHSA-hvrm-45r6-mjfj / GHSA-w62v-xxxg-mg59: repeated-header drop, JSX context leakage, JSX escaping bypass. Remove when hono >=4.12.27.
# GHSA-54fx-42gc-7vw4 / GHSA-79qm-7rj5-m7r9 / GHSA-f23p-vx2j-j53r: language-middleware DoS, proxy-helper header handling, memo() cross-request SSR leakage. Remove when hono >=4.12.34.
# GHSA-gqvv-2mrq-wpjv / GHSA-crvj-82cr-hjcx / GHSA-g6gw-c38x-mqfc: toSSG() writes outside output dir, query parser reads past fragment, parseBody() dot-notation memory exhaustion. Remove when hono >=4.13.5.
# GHSA-hxh3-vqpv-xpqv: unescaped plain strings in JSX boundary components (XSS). Remove when hono >=4.13.7.
"hono@<4.13.7": "4.13.7"
# GHSA-q8mj-m7cp-5q26: qs.stringify DoS. Remove when direct dependency upgrades qs >=6.15.2.
# GHSA-x5fp-wj9c-mxmx / GHSA-4mjr-xmp4-gh2g: array-limit bypass via bracket-key comma parsing, DoS via attacker-controlled isBuffer. Remove when direct dependency upgrades qs >=6.16.0.
"qs@>=6.11.1 <6.16.0": "6.16.0"
# GHSA-v2v4-37r5-5v8g: XSS in Address6 HTML-emitting methods. Remove when direct dependency upgrades ip-address >=10.1.1.
# GHSA-22jq-vg5j-6vgg / GHSA-4xrf-jv44-h6hh / GHSA-mwp4-54f8-5fhr: IPv4-mapped/NAT64 misclassification, CIDR-suffix special-use bypass, leading-zero octal SSRF. Remove when direct dependency upgrades ip-address >=10.3.1.
# GHSA-2vr4-cq9g-pvrc / GHSA-rpw4-54j3-4h4q: NAT64 local-use range and wrong link-local prefix enable SSRF/trust-boundary bypass. Remove when direct dependency upgrades ip-address >=10.5.1.
# GHSA-j6r3-76f7-8jcv / GHSA-h3mg-xc3c-68pw: cross-family subnet compare admits out-of-range addresses, unbounded parse diagnostic stalls process. Remove when direct dependency upgrades ip-address >=10.7.1.
"ip-address@<=10.7.0": "10.7.1"
# GHSA-h67p-54hq-rp68: quadratic-complexity DoS in merge key handling. Remove when js-yaml 3.x >=3.15.0.
# GHSA-5p4m-2wfm-xmqj: quadratic CPU consumption in !!omap resolution. Remove when js-yaml 3.x >=3.15.1.
# GHSA-2883-xcg3-v3hh: maxTotalMergeKeys does not limit CPU use for empty merge sources. Remove when js-yaml 3.x >=3.15.2.
"js-yaml@<3.15.2": "3.15.2"
# GHSA-h67p-54hq-rp68 / GHSA-52cp-r559-cp3m: quadratic-complexity DoS in merge key handling. Remove when js-yaml 4.x >=4.3.0.
# GHSA-5p4m-2wfm-xmqj: quadratic CPU consumption in !!omap resolution. Remove when js-yaml 4.x >=4.3.1.
# GHSA-2883-xcg3-v3hh: maxTotalMergeKeys does not limit CPU use for empty merge sources. Remove when js-yaml 4.x >=4.3.2.
"js-yaml@>=4.0.0 <4.3.2": "4.3.2"
# GHSA-4x5r-pxfx-6jf8: arbitrary file read via sourceMappingURL. Remove when @babel/core >=7.29.6.
"@babel/core@<=7.29.0": "7.29.7"
# GHSA-xffm-g5w8-qvg7: ReDoS in ConfigCommentParser. Remove when @eslint/plugin-kit >=0.3.4.
"@eslint/plugin-kit@<0.3.4": "0.3.4"
# GHSA-3jxr-9vmj-r5cp: exponential-time expansion of consecutive non-expanding {} groups. Remove when brace-expansion 1.x >=1.1.16.
# GHSA-mh99-v99m-4gvg / GHSA-rgw5-rvv9-x895: DoS via unbounded expansion length / unbounded intermediate arrays. Remove when brace-expansion 1.x >=1.1.18.
# GHSA-6j4f-fj2g-mc7p / GHSA-qhr7-859c-m2p7: uncontrolled recursion in parseCommaParts / nested brace groups causing stack exhaustion. Remove when brace-expansion 1.x >=1.1.20.
# GHSA-q2hr-2g5m-vwhr: quadratic-time expansion of the `{a},b}` rewrite. Remove when brace-expansion 1.x >=1.1.21.
"brace-expansion@<1.1.21": "1.1.21"
# GHSA-jxxr-4gwj-5jf2 / GHSA-3jxr-9vmj-r5cp: brace range / exponential-time expansion DoS. Remove when brace-expansion >=5.0.7.
# GHSA-mh99-v99m-4gvg / GHSA-rgw5-rvv9-x895: DoS via unbounded expansion length / unbounded intermediate arrays. Remove when brace-expansion 5.x >=5.0.9.
# GHSA-6j4f-fj2g-mc7p / GHSA-qhr7-859c-m2p7 / GHSA-q2hr-2g5m-vwhr: uncontrolled recursion stack exhaustion, quadratic-time `{a},b}` rewrite. Remove when brace-expansion 5.x >=5.0.12.
"brace-expansion@>=4.0.0 <5.0.12": "5.0.12"
# GHSA-v2hh-gcrm-f6hx / GHSA-4c8g-83qw-93j6: host confusion via backslash authority / failed IDN canonicalization. Remove when fast-uri >=3.1.4.
# GHSA-7p8r-x3mc-p8w7: host confusion via backslash authority introducer. Remove when fast-uri >=3.1.5.
# GHSA-jqff-g426-hqxp / GHSA-f65p-4m7j-42xc / GHSA-fph4-wmhf-6fwf / GHSA-5jgf-p345-68v8: host confusion and SSRF via percent-encoding / IPv6 normalization flaws. Remove when fast-uri >=3.1.6.
# GHSA-qw65-cvwx-89v3 / GHSA-hrr3-gc8f-f4qj: authority injection via unvalidated port, inconsistent host case normalization. Remove when fast-uri >=3.1.8.
"fast-uri@<3.1.8": "3.1.8"
# GHSA-6qxp-vccf-f47h: OAuth client could send credentials to an authorization server chosen by the MCP server. Remove when eslint's dependency upgrades @modelcontextprotocol/sdk >=1.31.0.
"@modelcontextprotocol/sdk@>=1.12.0 <1.31.0": "1.31.0"
# GHSA-v422-hmwv-36x6: invalid limit value silently disables size enforcement. Remove when body-parser 2.x >=2.3.0.
"body-parser@>=2.0.0 <2.3.0": "2.3.0"
# GHSA-frvp-7c67-39w9: path traversal in serve-static on Windows via encoded backslash. Remove when @hono/node-server >=2.0.5
# GHSA-9mqv-5hh9-4cgg: unauthenticated memory-leak DoS via aborted WebSocket handshake. Remove when @hono/node-server >=2.0.10
# (requires @modelcontextprotocol/sdk >=1.30.0, which declares "^1.19.9 || ^2.0.5").
"@hono/node-server@<2.0.10": "2.0.10"
onlyBuiltDependencies:
- secp256k1
minimumReleaseAgeExclude:
# Matches the overrides above; these versions are very recent but required for the security fixes.
- "@eslint/plugin-kit@0.3.4"
- "ip-address@10.7.1"
- "qs@6.16.0"
- "brace-expansion@1.1.21"
- "brace-expansion@5.0.12"
- "@babel/core@7.29.7"
- "js-yaml@3.15.2"
- "js-yaml@4.3.2"
- "tar@7.5.21"
- "hono@4.13.7"
- "fast-uri@3.1.8"
- "body-parser@2.3.0"
- "@hono/node-server@2.0.10"
- "@modelcontextprotocol/sdk@1.31.0"
# Build-script approvals read by newer pnpm (11+ fails the install on any unlisted build script).
# - cpu-features: optional runtime dep of the CLI; src/node/install.ts falls back to the portable CKB
# binary when it is not compiled, and it is kept external in the ncc bundle so end users build it
# on their own install. Nothing in this repo's build/tests needs the native addon.
# - unrs-resolver: its postinstall only checks for the prebuilt @unrs/resolver-binding-* package.
allowBuilds:
cpu-features: false
unrs-resolver: false