 
|
b8c34645c9
|
chore(deps): clean npm install — fix CVEs, silence warnings (#1782)
* chore(deps): clean npm install — fix CVEs, silence warnings
- bump undici 7.24.6 → 7.28.0 (7 high CVEs: TLS bypass, header injection,
DoS, cache poisoning, SameSite downgrade, cross-origin routing)
- bump ws 8.20.0 → 8.21.0 (2 high CVEs: uninitialized memory disclosure,
memory exhaustion DoS)
- add allowScripts for sharp + protobufjs to silence install-script warnings
- vendor node-domexception shim (re-exports native DOMException) and override
the deprecated polyfill pulled transitively by google-auth-library →
gaxios → node-fetch@3 → fetch-blob
Result: `npm install` reports 0 vulnerabilities, 0 warnings.
Co-Authored-By: OpenClaude <openclaude@gitlawb.com>
* chore(deps): update bun.lock for undici/ws bumps and node-domexception override
CI runs `bun install --frozen-lockfile`, which requires bun.lock to match
package.json. The previous commit bumped undici/ws and added the
node-domexception shim override but didn't include the regenerated lockfile,
causing frozen-lockfile CI to fail.
Co-Authored-By: OpenClaude <openclaude@gitlawb.com>
* fix(publish): include vendor/node-domexception-shim in npm tarball
The file: override in package.json points at vendor/node-domexception-shim,
but the files array didn't list vendor/, so npm pack excluded it. End-user
npm installs would fail resolving the override.
Add vendor/node-domexception-shim/ to the files array. Verified via
npm pack --dry-run: tarball now contains both shim files (12 → 14 files).
Addresses reviewer finding #1.
Co-Authored-By: OpenClaude <openclaude@gitlawb.com>
---------
Co-authored-by: OpenClaude <openclaude@gitlawb.com>
|
2026-06-25 09:26:11 +08:00 |
|