chore(deps): coordinated security sweep for open Dependabot alerts (#1475)

This commit is contained in:
4gray authored and GitHub committed 2026-08-23 13:56:00 +02:00
1 parent 7efb8c4f66
commit d6a9c23148
6 files changed
+1251 -1778

No files matched your search

@@ -0,0 +1,10 @@
---
type: internal
area: deps
---
Coordinated security dependency sweep closing all open Dependabot alerts: the
two runtime-scope advisories (js-yaml YAML-parsing DoS reached through
electron-updater, fast-uri host confusion reached through electron-conf) plus
the dev-only clusters — Astro 5→7 for the website, hono, undici, postcss and
a dozen other transitive bumps via pnpm overrides.
+3 -2
View File
@@ -1,13 +1,14 @@
// @ts-check // @ts-check
import { defineConfig } from 'astro/config'; import { defineConfig } from 'astro/config';
import tailwind from '@astrojs/tailwind';
import sitemap from '@astrojs/sitemap'; import sitemap from '@astrojs/sitemap';
import mdx from '@astrojs/mdx'; import mdx from '@astrojs/mdx';
// Tailwind (v3) is applied via apps/website/postcss.config.mjs — the
// @astrojs/tailwind integration only supports Astro <= 5.
// https://astro.build/config // https://astro.build/config
export default defineConfig({ export default defineConfig({
site: 'https://4gray.github.io', site: 'https://4gray.github.io',
base: '/iptvnator', base: '/iptvnator',
outDir: '../../dist/apps/website', outDir: '../../dist/apps/website',
integrations: [tailwind(), sitemap(), mdx()], integrations: [sitemap(), mdx()],
}); });
+15
View File
@@ -0,0 +1,15 @@
// Replaces the deprecated @astrojs/tailwind integration (Astro <= 5 only):
// Tailwind v3 runs as a plain PostCSS plugin, which Astro/Vite picks up
// automatically from this file. The config path is resolved explicitly so the
// build does not depend on the process working directory.
import { fileURLToPath } from 'node:url';
import autoprefixer from 'autoprefixer';
import tailwindcss from 'tailwindcss';
const tailwindConfig = fileURLToPath(
new URL('./tailwind.config.mjs', import.meta.url),
);
export default {
plugins: [tailwindcss({ config: tailwindConfig }), autoprefixer()],
};
+1 -1
View File
@@ -27,7 +27,7 @@ export default [
...nx.configs['flat/typescript'], ...nx.configs['flat/typescript'],
...nx.configs['flat/javascript'], ...nx.configs['flat/javascript'],
{ {
ignores: ['**/dist'], ignores: ['**/dist', '**/.astro'],
}, },
{ {
files: ['**/*.ts', '**/*.tsx', '**/*.js', '**/*.jsx'], files: ['**/*.ts', '**/*.tsx', '**/*.js', '**/*.jsx'],
+26 -10
View File
@@ -147,9 +147,8 @@
"@angular/platform-browser-dynamic": "21.2.19", "@angular/platform-browser-dynamic": "21.2.19",
"@angular/router": "21.2.19", "@angular/router": "21.2.19",
"@angular/service-worker": "21.2.19", "@angular/service-worker": "21.2.19",
"@astrojs/mdx": "4.3.13", "@astrojs/mdx": "7.0.7",
"@astrojs/sitemap": "3.7.3", "@astrojs/sitemap": "3.7.3",
"@astrojs/tailwind": "6.0.2",
"@electron/asar": "3.4.1", "@electron/asar": "3.4.1",
"@eslint/eslintrc": "3.3.6", "@eslint/eslintrc": "3.3.6",
"@eslint/js": "^9.38.0", "@eslint/js": "^9.38.0",
@@ -188,7 +187,9 @@
"@typescript-eslint/parser": "^8.67.0", "@typescript-eslint/parser": "^8.67.0",
"@typescript-eslint/utils": "^8.67.0", "@typescript-eslint/utils": "^8.67.0",
"angular-eslint": "21.4.0", "angular-eslint": "21.4.0",
"astro": "5.18.1", "astro": "7.2.4",
"autoprefixer": "10.5.4",
"cookie": "2.0.1",
"cors": "2.8.6", "cors": "2.8.6",
"drizzle-kit": "0.31.10", "drizzle-kit": "0.31.10",
"electron": "^43.3.0", "electron": "^43.3.0",
@@ -201,6 +202,7 @@
"eslint-plugin-playwright": "^1.6.2", "eslint-plugin-playwright": "^1.6.2",
"express": "5.2.1", "express": "5.2.1",
"globals": "15.9.0", "globals": "15.9.0",
"html-escaper": "3.0.3",
"istanbul-lib-coverage": "3.2.2", "istanbul-lib-coverage": "3.2.2",
"istanbul-lib-report": "3.0.1", "istanbul-lib-report": "3.0.1",
"istanbul-reports": "3.2.0", "istanbul-reports": "3.2.0",
@@ -211,6 +213,7 @@
"jest-util": "^30.4.1", "jest-util": "^30.4.1",
"jsonc-eslint-parser": "^2.1.0", "jsonc-eslint-parser": "^2.1.0",
"material-design-icons-iconfont": "6.7.0", "material-design-icons-iconfont": "6.7.0",
"mrmime": "2.0.1",
"ng-mocks": "14.17.1", "ng-mocks": "14.17.1",
"nx": "22.7.8", "nx": "22.7.8",
"nx-electron": "22.0.0", "nx-electron": "22.0.0",
@@ -223,33 +226,46 @@
"tsx": "4.23.12", "tsx": "4.23.12",
"typescript": "5.9.3", "typescript": "5.9.3",
"typescript-eslint": "^8.67.0", "typescript-eslint": "^8.67.0",
"yaml": "2.9.0" "yaml": "2.9.0",
"zod": "4.3.6"
}, },
"pnpm": { "pnpm": {
"overrides": { "overrides": {
"@hono/node-server@1.19.9": "1.19.14", "@esbuild-kit/core-utils>esbuild": "0.25.12",
"@hono/node-server@1.19.9": "1.19.17",
"@xmldom/xmldom@0.8.11": "0.8.13", "@xmldom/xmldom@0.8.11": "0.8.13",
"ajv@6.12.6": "6.14.0", "ajv@6.12.6": "6.14.0",
"ajv@8.17.1": "8.18.0", "ajv@8.17.1": "8.18.0",
"brace-expansion@1.1.12": "1.1.13", "brace-expansion@1.1.12": "1.1.18",
"defu@6.1.4": "6.1.6", "defu@6.1.4": "6.1.6",
"devalue@5.6.2": "5.6.4", "devalue@5.6.2": "5.6.4",
"express-rate-limit@8.2.1": "8.3.0", "express-rate-limit@8.2.1": "8.3.0",
"fast-uri@3.1.0": "3.1.4", "fast-uri@3.1.0": "3.1.6",
"flatted@3.3.3": "3.4.2", "flatted@3.3.3": "3.4.2",
"follow-redirects@1.15.11": "1.16.0", "follow-redirects@1.15.11": "1.16.0",
"form-data@4.0.5": "4.0.6", "form-data@4.0.5": "4.0.6",
"h3@1.15.5": "1.15.10", "h3@1.15.5": "1.15.10",
"hono@4.12.0": "4.12.14", "hono@4.12.0": "4.12.34",
"immutable@5.1.4": "5.1.5", "immutable@5.1.4": "5.1.9",
"js-yaml@4.1.1": "4.3.0", "ip-address@10.1.0": "10.5.0",
"js-yaml@4.1.1": "4.3.1",
"js-yaml@4.3.0": "4.3.1",
"jsdom>ws": "8.21.3",
"lodash-es@4.17.22": "4.18.1", "lodash-es@4.17.22": "4.18.1",
"minimatch@3.1.2": "3.1.5",
"node-forge@1.3.3": "1.4.0", "node-forge@1.3.3": "1.4.0",
"path-to-regexp@0.1.12": "0.1.13", "path-to-regexp@0.1.12": "0.1.13",
"picomatch@2.3.1": "2.3.2", "picomatch@2.3.1": "2.3.2",
"picomatch@4.0.3": "4.0.5",
"postcss@8.5.6": "8.5.26",
"qs@6.14.1": "6.15.3",
"rollup@4.52.3": "4.59.0", "rollup@4.52.3": "4.59.0",
"serialize-javascript@6.0.2": "7.1.0",
"smol-toml@1.6.0": "1.6.1", "smol-toml@1.6.0": "1.6.1",
"svgo@3.3.2": "3.3.3", "svgo@3.3.2": "3.3.3",
"svgo@4.0.0": "4.0.2",
"undici@7.28.0": "7.29.0",
"uuid@8.3.2": "11.1.1",
"yaml@1.10.2": "1.10.3" "yaml@1.10.2": "1.10.3"
}, },
"patchedDependencies": { "patchedDependencies": {
+1196 -1765
View File
File diff suppressed because it is too large. Load diff