Skip to content

Commit 4c56f8c

Browse files
authored
chore: pin dependencies and fix tar vulnerability (#31)
- Pin all dependencies in package.json to specific versions as per enterprise requirements. - Add pnpm override for 'tar' to version 7.5.4 to fix high-severity vulnerability (Dependabot #42). - Update pnpm-lock.yaml to reflect changes.
1 parent d2c848e commit 4c56f8c

2 files changed

Lines changed: 91 additions & 36 deletions

File tree

package.json

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -13,12 +13,20 @@
1313
},
1414
"devDependencies": {
1515
"prettier": "3.8.1",
16-
"turbo": "2.7.5",
16+
"turbo": "2.7.6",
1717
"typescript": "5.9.3",
1818
"rimraf": "6.1.2"
1919
},
20-
"packageManager": "pnpm@10.28.1",
20+
"packageManager": "pnpm@10.28.2",
2121
"engines": {
2222
"node": ">=18.18.0"
23+
},
24+
"pnpm": {
25+
"overrides": {
26+
"tar": "7.5.4"
27+
},
28+
"comments": {
29+
"overrides": "Security fixes for transitive dependencies. Remove when upstream packages update: tar (Dependabot #42) - awaiting @tailwindcss/oxide update"
30+
}
2331
}
2432
}

0 commit comments

Comments
 (0)