Files
iptvnator/package.json
T
4grayandClaude Opus 5 d2316fafe9 fix(deps): patch transitive runtime CVEs via pnpm overrides
Closes 13 runtime-scope Dependabot advisories that Dependabot itself
cannot fix: the vulnerable packages are all transitive, so the bot has no
lever until each parent publishes a release widening its own pin.

Overrides added (pinned-source form, matching existing convention):

- @xmldom/xmldom 0.8.11 -> 0.8.13  (5 high) via video.js -> mpd-parser
- fast-uri       3.1.0  -> 3.1.4   (4 high) via electron-conf -> ajv
- js-yaml        4.1.1  -> 4.3.0   (2)      via electron-updater
- form-data      4.0.5  -> 4.0.6   (1 high) via axios
- ajv            8.17.1 -> 8.18.0  (1)      via electron-conf

Every target stays inside its parent's declared semver range. For xmldom,
fast-uri and js-yaml the newest published version is *outside* that range
(0.9.x / 4.x / 5.x), so "latest" would have broken them - the new doc
records that constraint.

Deliberately excluded:

- axios and uuid are direct deps already covered by open Dependabot PRs
  (#1251 bumps axios 1.16.0 -> 1.18.1; #1252 covers uuid). Hand-bumping
  them here would only conflict on the lockfile.
- undici (7 advisories) is labelled runtime scope but every path to it is
  build tooling - electron -> @electron/get, @angular/build, and
  @module-federation/dts-plugin. It is not in the packaged app.

Note on reachability: xmldom arrives via video.js -> VHS -> mpd-parser,
but the app routes every .mpd to Shaka, which uses its own DASH parser.
The code ships but is not on the playback path, so this is defence in
depth rather than closing a live hole. The genuinely reachable one is
js-yaml, which electron-updater uses to parse latest.yml from releases.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-25 22:25:38 +02:00

250 lines
11 KiB
JSON

{
"name": "iptvnator",
"version": "0.23.0",
"license": "MIT",
"description": "IPTV player application.",
"homepage": "https://github.com/4gray/iptvnator",
"author": {
"name": "4gray",
"email": "fourgray@proton.me"
},
"keywords": [
"angular",
"electron",
"typescript",
"m3u",
"m3u8",
"player",
"iptv",
"video",
"tv"
],
"scripts": {
"postinstall": "electron-builder install-app-deps",
"build:frontend": "nx build web",
"build:frontend:pwa": "nx build web --configuration=pwa",
"build:backend": "nx build electron-backend --configuration=production",
"serve:frontend": "nx serve web --no-tui",
"serve:frontend:pwa": "nx serve web --configuration=pwa --no-tui",
"serve:backend": "nx serve electron-backend",
"serve:marketing-demo": "nx run-many --target=serve --projects=xtream-mock-server,electron-backend --parallel=2",
"serve:marketing-demo:web": "nx run-many --target=serve --projects=xtream-mock-server,web --parallel=2",
"test:frontend": "nx test web",
"test:backend": "nx test electron-backend",
"test:unit:all": "nx run-many --target=test --all --parallel=3",
"test:unit:ci": "nx run-many --target=test --all --parallel=3 --output-style=static",
"coverage:unit:ci": "node tools/coverage/run-tier-a-coverage.mjs",
"coverage:merge": "node tools/coverage/merge-coverage.mjs",
"coverage:health": "node tools/coverage/coverage-health.mjs",
"coverage:policy:check": "node tools/coverage/check-coverage-policy.mjs",
"coverage:ci": "pnpm run coverage:policy:check && pnpm run coverage:unit:ci && pnpm run coverage:merge && node tools/coverage/coverage-health.mjs --require-report",
"coverage:e2e:summary": "node tools/coverage/e2e-semantic-summary.mjs",
"coverage:e2e:v8:web": "node tools/coverage/e2e-v8-web.mjs",
"typecheck:web": "tsc -p apps/web/tsconfig.app.json --noEmit",
"typecheck:backend": "tsc -p apps/electron-backend/tsconfig.app.json --noEmit",
"typecheck:ci": "pnpm run typecheck:web && pnpm run typecheck:backend",
"verify:package-layout": "node tools/packaging/verify-electron-package-layout.mjs",
"embedded-mpv:build-native:homebrew": "IPTVNATOR_EMBEDDED_MPV_ALLOW_HOMEBREW=1 nx run electron-backend:build-embedded-mpv",
"embedded-mpv:build-runtime": "node tools/embedded-mpv/build-macos-runtime.mjs",
"embedded-mpv:build-runtime:linux": "node tools/embedded-mpv/build-linux-runtime.mjs",
"embedded-mpv:stage-runtime": "node tools/embedded-mpv/stage-runtime.mjs",
"embedded-mpv:stage-runtime:macos": "node tools/embedded-mpv/stage-macos-runtime.mjs",
"embedded-mpv:stage-runtime:windows-archive": "node tools/embedded-mpv/stage-windows-runtime-archive.mjs",
"serve:backend:embedded-mpv": "pnpm embedded-mpv:build-native:homebrew && IPTVNATOR_EMBEDDED_MPV_ALLOW_HOMEBREW=1 IPTVNATOR_ENABLE_EMBEDDED_MPV_EXPERIMENT=1 pnpm serve:backend",
"package:app": "nx run electron-backend:make --prepackageOnly",
"make:app": "nx run electron-backend:make",
"smoke:packaged": "node tools/testing/launch-packaged-electron.mjs",
"serve:website": "nx serve website",
"build:website": "nx build website",
"i18n:check": "node tools/i18n/check-drift.mjs",
"release:artwork:dry-run": "tsx tools/release/generate-marketing-artwork.ts --dry-run",
"release:artwork:manifest": "tsx tools/release/generate-marketing-artwork.ts --manifest",
"release:artwork:generate": "tsx tools/release/generate-marketing-artwork.ts --generate",
"release:artwork:validate": "tsx tools/release/generate-marketing-artwork.ts --validate",
"release:notes:validate": "node tools/release/build-release-notes.mjs --validate",
"release:notes:github": "node tools/release/build-release-notes.mjs --format github",
"release:notes:changelog": "node tools/release/build-release-notes.mjs --format changelog",
"release:notes:blog": "node tools/release/build-release-notes.mjs --format blog",
"lint": "nx run-many --target=lint --all",
"build": "nx build electron-backend"
},
"private": true,
"packageManager": "pnpm@10.33.0+sha512.10568bb4a6afb58c9eb3630da90cc9516417abebd3fabbe6739f0ae795728da1491e9db5a544c76ad8eb7570f5c4bb3d6c637b2cb41bfdcdb47fa823c8649319",
"dependencies": {
"@angular/animations": "21.2.17",
"@angular/cdk": "21.2.14",
"@angular/common": "21.2.17",
"@angular/compiler": "21.2.17",
"@angular/core": "21.2.17",
"@angular/forms": "21.2.17",
"@angular/material": "21.2.14",
"@angular/platform-browser": "21.2.17",
"@angular/platform-browser-dynamic": "21.2.17",
"@angular/router": "21.2.17",
"@ngrx/effects": "21.0.1",
"@ngrx/entity": "21.0.1",
"@ngrx/router-store": "21.0.1",
"@ngrx/signals": "21.0.1",
"@ngrx/store": "21.0.1",
"@ngrx/store-devtools": "21.0.1",
"@ngx-pwa/local-storage": "21.0.0",
"@yangkghjh/videojs-aspect-ratio-panel": "0.0.1",
"angularx-qrcode": "21.0.4",
"artplayer": "5.3.0",
"axios": "1.16.0",
"better-sqlite3": "12.9.0",
"date-fns": "4.1.0",
"drizzle-orm": "0.45.2",
"electron-conf": "1.3.0",
"electron-updater": "6.8.9",
"epg-parser": "^0.1.6",
"fix-path": "5.0.0",
"hls.js": "1.6.13",
"iptv-playlist-parser": "github:4gray/iptv-playlist-parser#v0.15.2-iptvnator.2",
"marked": "18.0.5",
"mpegts.js": "1.8.0",
"ms": "2.1.3",
"ngx-indexed-db": "21.0.0",
"ngx-skeleton-loader": "11.3.0",
"rxjs": "7.8.2",
"saxes": "6.0.0",
"shaka-player": "5.2.1",
"uuid": "9.0.0",
"video.js": "8.23.4",
"videojs-contrib-quality-levels": "4.1.0",
"videojs-quality-selector-hls": "1.1.1",
"zone.js": "~0.15.1"
},
"devDependencies": {
"@angular-devkit/core": "21.2.17",
"@angular-devkit/schematics": "21.2.17",
"@angular-eslint/builder": "21.3.1",
"@angular-eslint/eslint-plugin": "21.3.1",
"@angular-eslint/eslint-plugin-template": "21.3.1",
"@angular-eslint/schematics": "21.3.1",
"@angular-eslint/template-parser": "21.3.1",
"@angular/build": "21.2.17",
"@angular/cli": "21.2.17",
"@angular/common": "21.2.17",
"@angular/compiler": "21.2.17",
"@angular/compiler-cli": "21.2.17",
"@angular/core": "21.2.17",
"@angular/forms": "21.2.17",
"@angular/language-service": "21.2.17",
"@angular/platform-browser": "21.2.17",
"@angular/platform-browser-dynamic": "21.2.17",
"@angular/router": "21.2.17",
"@angular/service-worker": "21.2.17",
"@astrojs/mdx": "4.3.13",
"@astrojs/sitemap": "3.7.0",
"@astrojs/tailwind": "6.0.2",
"@electron/asar": "3.4.1",
"@eslint/eslintrc": "3.3.1",
"@eslint/js": "^9.38.0",
"@faker-js/faker": "10.3.0",
"@fontsource/crimson-pro": "5.2.8",
"@fontsource/dm-sans": "5.2.8",
"@fontsource/jetbrains-mono": "5.2.8",
"@fontsource/roboto": "5.2.10",
"@ngrx/eslint-plugin": "^21.0.1",
"@ngx-translate/core": "16.0.4",
"@ngx-translate/http-loader": "16.0.1",
"@nx/angular": "22.7.1",
"@nx/devkit": "22.7.1",
"@nx/esbuild": "22.7.1",
"@nx/eslint": "22.7.1",
"@nx/eslint-plugin": "22.7.1",
"@nx/jest": "22.7.1",
"@nx/js": "22.7.1",
"@nx/playwright": "22.7.1",
"@nx/web": "22.7.1",
"@nx/workspace": "22.7.1",
"@playwright/test": "^1.36.0",
"@schematics/angular": "21.2.9",
"@swc-node/register": "1.11.1",
"@swc/core": "1.15.8",
"@swc/helpers": "0.5.18",
"@tailwindcss/typography": "0.5.19",
"@types/better-sqlite3": "^7.6.12",
"@types/cors": "2.8.19",
"@types/express": "5.0.6",
"@types/jest": "^30.0.0",
"@types/mocha": "9.0.0",
"@types/node": "20.19.9",
"@types/uuid": "^10.0.0",
"@types/video.js": "7.3.29",
"@typescript-eslint/eslint-plugin": "^8.46.2",
"@typescript-eslint/parser": "^8.46.2",
"@typescript-eslint/utils": "^8.46.2",
"angular-eslint": "21.3.1",
"astro": "5.18.1",
"cors": "2.8.6",
"drizzle-kit": "0.31.5",
"electron": "^41.7.2",
"electron-builder": "^26.0.12",
"electron-playwright-helpers": "1.8.2",
"esbuild": "0.28.1",
"eslint": "^9.8.0",
"eslint-config-prettier": "^10.1.8",
"eslint-plugin-import": "2.32.0",
"eslint-plugin-playwright": "^1.6.2",
"express": "5.2.1",
"globals": "15.9.0",
"istanbul-lib-coverage": "3.2.2",
"istanbul-lib-report": "3.0.1",
"istanbul-reports": "3.2.0",
"jest": "^30.0.2",
"jest-environment-jsdom": "^30.0.2",
"jest-environment-node": "^30.0.2",
"jest-preset-angular": "~15.0.0",
"jest-util": "^30.0.2",
"jsonc-eslint-parser": "^2.1.0",
"material-design-icons-iconfont": "6.7.0",
"ng-mocks": "14.15.1",
"nx": "22.7.1",
"nx-electron": "22.0.0",
"prettier": "^3.8.1",
"sharp": "0.34.5",
"tailwindcss": "^3.4.19",
"ts-jest": "^29.4.5",
"ts-node": "10.9.2",
"tslib": "^2.8.1",
"tsx": "4.21.0",
"typescript": "5.9.3",
"typescript-eslint": "^8.46.2",
"yaml": "2.8.2"
},
"pnpm": {
"overrides": {
"@hono/node-server@1.19.9": "1.19.14",
"@xmldom/xmldom@0.8.11": "0.8.13",
"ajv@6.12.6": "6.14.0",
"ajv@8.17.1": "8.18.0",
"brace-expansion@1.1.12": "1.1.13",
"defu@6.1.4": "6.1.6",
"devalue@5.6.2": "5.6.4",
"express-rate-limit@8.2.1": "8.3.0",
"fast-uri@3.1.0": "3.1.4",
"flatted@3.3.3": "3.4.2",
"follow-redirects@1.15.11": "1.16.0",
"form-data@4.0.5": "4.0.6",
"h3@1.15.5": "1.15.10",
"hono@4.12.0": "4.12.14",
"immutable@5.1.4": "5.1.5",
"js-yaml@4.1.1": "4.3.0",
"lodash-es@4.17.22": "4.18.1",
"node-abi@3.85.0": "3.92.0",
"node-forge@1.3.3": "1.4.0",
"path-to-regexp@0.1.12": "0.1.13",
"picomatch@2.3.1": "2.3.2",
"rollup@4.52.3": "4.59.0",
"smol-toml@1.6.0": "1.6.1",
"svgo@3.3.2": "3.3.3",
"yaml@1.10.2": "1.10.3"
},
"patchedDependencies": {
"nx-electron@22.0.0": "patches/nx-electron@22.0.0.patch"
}
}
}