Commit 15958e4
committed
deps: close 14 dependabot alerts via pnpm overrides
- hono ^4.12.14 (HTML injection, cookie bypass, path traversal, IP matching, serveStatic bypass)
- @hono/node-server ^1.19.13 (serveStatic bypass)
- vite ^8.0.5 (fs.deny bypass, arbitrary file read, .map path traversal)
- picomatch@2 ^2.3.2 + picomatch@4 ^4.0.4 (ReDoS, glob method injection)
Also bumps shadcn 4.1.1 → 4.3.0 and vitest 4.1.0 → 4.1.4 as a side
effect of the pnpm update that teed this up. Tests + build pass.1 parent d85cb48 commit 15958e4
2 files changed
Lines changed: 503 additions & 488 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
25 | | - | |
| 25 | + | |
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
| |||
37 | 37 | | |
38 | 38 | | |
39 | 39 | | |
40 | | - | |
| 40 | + | |
41 | 41 | | |
42 | | - | |
| 42 | + | |
43 | 43 | | |
44 | 44 | | |
45 | 45 | | |
| |||
54 | 54 | | |
55 | 55 | | |
56 | 56 | | |
57 | | - | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
58 | 67 | | |
0 commit comments