-
Notifications
You must be signed in to change notification settings - Fork 5
Expand file tree
/
Copy pathpnpm-workspace.yaml
More file actions
150 lines (148 loc) · 8.9 KB
/
Copy pathpnpm-workspace.yaml
File metadata and controls
150 lines (148 loc) · 8.9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
packages:
- packages/*
- packages/apps/*
- packages/plugins/*
- packages/qa/*
- packages/triggers/*
- packages/services/*
- packages/adapters/*
- packages/connectors/*
- apps/*
- examples/*
onlyBuiltDependencies:
- better-sqlite3
- esbuild
- mongodb-memory-server
- msw
- sharp
# Transitive-dependency version pins. pnpm v10 reads `overrides` from THIS file
# — the `pnpm.overrides` block in package.json is silently ignored — so all
# pins must live here (previously orphaned in package.json: minimatch, tar).
# - esbuild: GHSA-gv7w-rqvm-qjhr (high). tsup/tsx/vite pulled 0.27.7 / 0.28.0
# (< 0.28.1); force the patched line everywhere.
# - form-data: GHSA-hmw2-7cc7-3qxx (high) — CRLF injection via unescaped
# multipart field names. Pulled 4.0.5 transitively through @vscode/vsce;
# force the patched >=4.0.6 line. Fails `pnpm audit --audit-level=high` (CI).
# - undici: GHSA-vmh5-mc38-953g (high) — TLS cert validation bypass via
# dropped requestTls in SOCKS5 ProxyAgent. Pulled 7.27.2 through
# @vscode/vsce > cheerio (declares undici ^7.19.0); force the patched
# 7.28.0 line (stays in the 7.x major cheerio supports). CI audit gate.
# Then five more advisories landed on 7.28.0 itself — the version this pin
# had settled on (GHSA-4cwx-7wf7-3272 7.4 high, GHSA-jr45-8vmc-qm54 5.9,
# GHSA-8xcm-r25x-g524 / GHSA-v3r7-h72x-cjcm 4.8, GHSA-m8rv-5g2x-5cg5 4.2) —
# so the bound moves to <7.29.0 / ^7.29.0 (#5032). NOTE the recurring trap:
# an exclusive upper bound stops covering the very version it pinned once
# that version is itself flagged, so the selector AND the target must move
# together — same shape as the brace-expansion 5.0.8 → 5.0.9 lift (#4945).
# Still transitive-only via cheerio; @ai-sdk/provider-utils already resolves
# 7.29.0, so the two dedupe. jsdom's undici 8.9.0 is outside the selector
# and unaffected.
# - @better-auth/scim: GHSA-j8v8-g9cx-5qf4 (high) — account/provider
# takeover. The advisory is patched only in >=1.7.0-beta.4 — there is NO
# stable patched release yet (npm `latest` is still on the 1.6.x line), so
# a pre-release pin is what clears the CI audit gate; revert to a stable
# `^1.7.x` line the moment one ships.
# Held at 1.7.0-rc.1 while the rest of the family moves to rc.2: rc.2 is a
# ground-up rewrite of this plugin — the `scimProvider` model and its
# generate-token endpoint are gone, replaced by code-defined connections
# plus six new models (scimUser, scimGroup, scimGroupMember, scimSubject,
# scimConnectionBinding, scimIdentityTombstone). Adopting it means new
# platform objects, retiring `sys_scim_provider`, and a new way for a
# tenant to register a connection — a feature migration (ADR-0071), not a
# version bump. rc.1's peer range accepts rc.2 core, and it still carries
# the advisory fix.
# - @better-auth/oauth-provider: GHSA-p2fr-6hmx-4528 — same better-auth
# monorepo and same situation as @better-auth/scim above. The fix first
# ships in the 1.7.0 pre-release line. Pin to 1.7.0-rc.2. The 1.7
# oauth-provider is exercised on the sign-in path and imports symbols
# (e.g. CLIENT_ASSERTION_TYPE) that only exist in @better-auth/core 1.7.x,
# so the ENTIRE better-auth family must move to 1.7.0-rc.2 together —
# mixing a 1.7 plugin with 1.6.x core throws "Cannot set properties of
# undefined (setting 'modelName')" during better-auth init and 500s every
# auth endpoint at runtime, and mixing rc.2 with rc.1 is the same class of
# hazard. The full family is pinned below; revert all of them to a stable
# `^1.7.x` line the moment one ships.
# IMPORTANT: these overrides do NOT ship with published packages — a
# downstream `npx create-objectstack` install resolves plugin-auth's own
# declared ranges. plugin-auth therefore pins the same exact 1.7.0-rc.2 in
# its dependencies (a `^1.6.23` range there resolved to the broken 1.6.23
# mix and 500'd every fresh 15.1.0 project). Keep both in sync — CI
# enforces this via scripts/check-override-consistency.mjs.
# - uuid: GHSA-w5hq-g745-h8pq (high) — pulled 8.3.2 transitively; the fix
# first lands in 11.1.1. Pin to the ^11.1.1 LTS line (uuid `legacy-11`
# dist-tag) rather than the latest major to keep the jump conservative.
# - postcss: GHSA-qx2v-qp2m-jg93 — a transitive path still resolves 8.4.31
# (the direct `apps/docs` dep already tracks ^8.5.x); force the patched
# ^8.5.10 line so the transitive copy is deduped onto it.
# - cookie: GHSA-pxg6-pf52-xh8x — pulled 0.6.0 transitively; force the
# patched 0.7.0 line (drop-in compatible).
# - svelte: GHSA-9rmh-mm8f-r9h6, GHSA-f3cj-j4f6-wq85, GHSA-pr6f-5x2q-rwfp,
# GHSA-rcqx-6q8c-2c42 — auto-installed (auto-install-peers) as an *optional*
# peer-of-a-peer via better-auth > @sveltejs/kit at 5.55.3. An `overrides`
# entry alone can't rewrite this resolution (pnpm rewrites the peer range
# but leaves the locked 5.55.3), so the patched line is pinned by BOTH this
# override AND a `svelte: ^5.55.7` devDependency in the root (private)
# package.json, which gives the peer a concrete version to dedupe onto.
# Keep both in sync; removing the root devDependency reintroduces 5.55.3.
# - @tootallnate/once: GHSA-vpq2-c234-7xj6 (low) — pulled 1.1.2 through a
# legacy agent chain; force the patched 2.0.1 line.
overrides:
esbuild: '>=0.28.1'
'minimatch@<10.2.3': '10.2.3'
'tar@>=2.0.0 <7.5.11': '^7.5.11'
'form-data@<4.0.6': '>=4.0.6'
'undici@>=7.23.0 <7.29.0': '^7.29.0'
# better-auth family — kept on one line (see @better-auth/oauth-provider note).
'better-auth@<1.7.0-rc.2': '1.7.0-rc.2'
'@better-auth/core@<1.7.0-rc.2': '1.7.0-rc.2'
# scim is deliberately held one pre-release BEHIND the rest of the family —
# see the @better-auth/scim note above. Do not "align" it without doing the
# connection/credential migration first.
'@better-auth/scim@<1.7.0-rc.1': '1.7.0-rc.1'
'@better-auth/oauth-provider@<1.7.0-rc.2': '1.7.0-rc.2'
'@better-auth/sso@<1.7.0-rc.2': '1.7.0-rc.2'
'@better-auth/drizzle-adapter@<1.7.0-rc.2': '1.7.0-rc.2'
'@better-auth/kysely-adapter@<1.7.0-rc.2': '1.7.0-rc.2'
'@better-auth/memory-adapter@<1.7.0-rc.2': '1.7.0-rc.2'
'@better-auth/mongo-adapter@<1.7.0-rc.2': '1.7.0-rc.2'
'@better-auth/prisma-adapter@<1.7.0-rc.2': '1.7.0-rc.2'
'@better-auth/telemetry@<1.7.0-rc.2': '1.7.0-rc.2'
'uuid@<11.1.1': '^11.1.1'
'postcss@<8.5.10': '^8.5.10'
'cookie@<0.7.0': '0.7.0'
svelte: '^5.55.7'
'@tootallnate/once@<2.0.1': '2.0.1'
# OSV batch 2026-07 — transitive-only fixes (no publishable package declares these):
# brace-expansion GHSA-mh99-v99m-4gvg (via minimatch@10.x), then GHSA-rgw5-rvv9-x895
# (7.5 high) which affects 5.0.8 itself — the version the first pin landed on — so the
# bound moves to <5.0.9. Still transitive-only through minimatch (ts-morph, eslint,
# @typescript-eslint, glob, @vscode/vsce, archiver); sharp GHSA-f88m-g3jw-g9cj
# (next optionalDep ^0.34.5 excludes the fix); react-router GHSA-qwww-vcr4-c8h2 has no
# 7.x fix — fumadocs-core peer allows 8.x and docs uses the next adapter, so jump to 8;
# @sveltejs/kit GHSA-866w-xmhq-wj7x/GHSA-wqjv-9729-c5q2 (better-auth optional peer);
# @hono/node-server GHSA-frvp-7c67-39w9 has no 1.x fix — @modelcontextprotocol/sdk
# declares ^1.19.9 and only imports getRequestListener, which 2.x still exports.
'brace-expansion@>=5.0.0 <5.0.9': '^5.0.9'
'sharp@>=0.34.0 <0.35.0': '^0.35.0'
'react-router@<8.3.0': '^8.3.0'
'@sveltejs/kit@<2.69.1': '^2.69.1'
'@hono/node-server@<2.0.5': '^2.0.10'
# OSV batch 2026-08 (#5032) — all three name a fixed version, so they are
# upgrades, not exemptions (the osv-scanner.toml route #4965 defines is for
# advisories with NO fix and does not apply here):
# fast-uri GHSA-7p8r-x3mc-p8w7 (7.5 high) — transitive-only via ajv@8.20.0
# (declares ^3.0.1), which reaches @modelcontextprotocol/sdk, objectql,
# secretlint and table. Nothing declares fast-uri directly.
# hono GHSA-8j4g-w8fx-2239 (5.3) — the one entry here that is NOT
# transitive-only: two versions resolved, 4.12.32 from our own packages
# and 4.12.33 pulled by @modelcontextprotocol/sdk. The override moves the
# transitive copy; the declared ranges are bumped to ^4.12.34 in lockstep
# (plugin-hono-server dependency, plugin-auth + @objectstack/hono
# devDependencies) so a downstream install — which never sees these
# overrides — resolves the same patched line that CI tested. The
# @objectstack/hono PEER range stays the permissive ^4.12.8 on purpose: a
# peer states what host hono we work against, and a host that pins an old
# hono owns that copy; narrowing it fixes nothing here and only breaks
# compatibility. check-override-consistency.mjs covers both forms.
'fast-uri@<3.1.5': '^3.1.5'
'hono@<4.12.34': '^4.12.34'