mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-08 17:06:15 -08:00
fix(deps): patch transitive runtime CVEs via pnpm overrides (#1258)
Closes 13 runtime-scope Dependabot advisories that Dependabot cannot fix itself: every vulnerable package here is transitive, so the bot has no lever until each parent publishes a release widening its own pin. Overrides added (pinned-source form, matching existing convention): - @xmldom/xmldom 0.8.11 -> 0.8.13 (5 high) via video.js -> mpd-parser - fast-uri 3.1.0 -> 3.1.4 (4 high) via electron-conf -> ajv - js-yaml 4.1.1 -> 4.3.0 (2) via electron-updater - form-data 4.0.5 -> 4.0.6 (1 high) via axios - ajv 8.17.1 -> 8.18.0 (1) via electron-conf Every target stays inside its parent's declared semver range. For xmldom, fast-uri and js-yaml the newest published version is outside that range (0.9.x / 4.x / 5.x), so "latest" would have broken them; the new doc records that constraint. Deliberately excluded: axios and uuid are direct deps already covered by open Dependabot PRs (#1251, #1252). undici is labelled runtime scope but every path to it is build tooling (electron -> @electron/get, @angular/build, @module-federation/dts-plugin) and it is not in the packaged app. Reachability: xmldom arrives via video.js -> VHS -> mpd-parser, but the app routes every .mpd to Shaka, which uses its own DASH parser, so that one is defence in depth. The genuinely reachable one is js-yaml, which electron-updater uses to parse latest.yml from releases. Adds docs/architecture/dependency-security-overrides.md and a .changes note. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
1 parent
3032cfa88d
commit
e91a7cde7a
4 files changed
+137
-52
No files matched your search
@@ -218,16 +218,21 @@
|
||||
"pnpm": {
|
||||
"overrides": {
|
||||
"@hono/node-server@1.19.9": "1.19.14",
|
||||
"@xmldom/xmldom@0.8.11": "0.8.13",
|
||||
"ajv@6.12.6": "6.14.0",
|
||||
"ajv@8.17.1": "8.18.0",
|
||||
"brace-expansion@1.1.12": "1.1.13",
|
||||
"defu@6.1.4": "6.1.6",
|
||||
"devalue@5.6.2": "5.6.4",
|
||||
"express-rate-limit@8.2.1": "8.3.0",
|
||||
"fast-uri@3.1.0": "3.1.4",
|
||||
"flatted@3.3.3": "3.4.2",
|
||||
"follow-redirects@1.15.11": "1.16.0",
|
||||
"form-data@4.0.5": "4.0.6",
|
||||
"h3@1.15.5": "1.15.10",
|
||||
"hono@4.12.0": "4.12.14",
|
||||
"immutable@5.1.4": "5.1.5",
|
||||
"js-yaml@4.1.1": "4.3.0",
|
||||
"lodash-es@4.17.22": "4.18.1",
|
||||
"node-abi@3.85.0": "3.92.0",
|
||||
"node-forge@1.3.3": "1.4.0",
|
||||
|
||||
Reference in new issue
Block a user