Skip to content

Commit 10b3308

Browse files
committed
langfuse-3: update dependencies to remediate CVEs (#72417)
- CVE-2026-41242 / GHSA-xq3m-2v4x-88gg (Critical) - protobufjs 7.4.0, 7.5.4 -> ^7.5.5 - GHSA-q4gf-8mx6-v5v3 (High) - next 16.2.1 -> ^16.2.3 - GHSA-39q2-94rc-95cp (Medium) - dompurify 3.3.3 -> ^3.4.0 - GHSA-r4q5-vmmm-2653 (Medium) - follow-redirects 1.15.11 -> ^1.16.0 - CVE-2026-40190 / GHSA-fw9q-39r9-c252 (Medium) - langsmith 0.4.12 -> ^0.5.19 - GHSA-rr7j-v2q5-chgv (Medium) - langsmith 0.4.12 -> ^0.5.19 - CVE-2026-33532 / GHSA-48c2-rrv3-qjmp (Medium) - yaml 2.8.1 -> ^2.8.3 Signed-off-by: Brian Carey <brian.carey@chainguard.dev> Export: b0fab1f4edfaa2138ee8b76161401f63c22ff5c4
1 parent 5f87f5d commit 10b3308

1 file changed

Lines changed: 13 additions & 5 deletions

File tree

langfuse-3.yaml

Lines changed: 13 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
package:
22
name: langfuse-3
3-
epoch: 5
3+
epoch: 6
44
version: "3.164.0"
55
description: "Langfuse webapp"
66
copyright:
@@ -77,7 +77,7 @@ pipeline:
7777
"pnpm.overrides.body-parser=^2.2.1" \
7878
"pnpm.overrides.ws=^8.17.1" \
7979
"pnpm.overrides.brace-expansion=^5.0.5" \
80-
"pnpm.overrides.dompurify=^3.3.2" \
80+
"pnpm.overrides.dompurify=^3.4.0" \
8181
"pnpm.overrides.solid-js=^1.9.4" \
8282
"pnpm.overrides.go=^1.23.10" \
8383
"pnpm.overrides.form-data=>=2.5.4 <3.0.0 || >=4.0.4 <5.0.0" \
@@ -104,7 +104,7 @@ pipeline:
104104
"pnpm.overrides.ajv=^8.18.0" \
105105
"pnpm.overrides.minimatch=^10.2.3" \
106106
"pnpm.overrides.svelte=^5.51.5" \
107-
"pnpm.overrides.langsmith=^0.4.6" \
107+
"pnpm.overrides.langsmith=^0.5.19" \
108108
"pnpm.overrides.basic-ftp=^5.2.1" \
109109
"pnpm.overrides.rollup=^4.59.0" \
110110
"pnpm.overrides.express-rate-limit=^8.2.2" \
@@ -113,7 +113,10 @@ pipeline:
113113
"pnpm.overrides.effect=^3.20.0" \
114114
"pnpm.overrides.defu=^6.1.5" \
115115
"pnpm.overrides.@tootallnate/once =^3.0.1" \
116-
"pnpm.overrides.nodmailer=^8.0.4"
116+
"pnpm.overrides.nodmailer=^8.0.4" \
117+
"pnpm.overrides.protobufjs=^7.5.5" \
118+
"pnpm.overrides.follow-redirects=^1.16.0" \
119+
"pnpm.overrides.next=^16.2.3"
117120
118121
pnpm install --ignore-scripts --no-frozen-lockfile
119122
@@ -272,7 +275,12 @@ subpackages:
272275
"pnpm.overrides.basic-ftp=^5.2.0" \
273276
"pnpm.overrides.rollup=^4.59.0" \
274277
"devDependencies.webpack=^5.104.1" \
275-
"pnpm.overrides.effect=^3.20.0"
278+
"pnpm.overrides.effect=^3.20.0" \
279+
"pnpm.overrides.protobufjs=^7.5.5" \
280+
"pnpm.overrides.dompurify=^3.4.0" \
281+
"pnpm.overrides.follow-redirects=^1.16.0" \
282+
"pnpm.overrides.yaml=^2.8.3" \
283+
"pnpm.overrides.langsmith=^0.5.19"
276284
277285
pnpm run build --filter=worker
278286
- name: "Move output into directories"

0 commit comments

Comments
 (0)