Commit a99514b
authored
chore(deps): resolve remaining Dependabot alerts via cross-major dependency upgrades (#13449)
* chore(deps): resolve remaining Dependabot alerts via dependency upgrades
Cross-major security upgrades that pnpm overrides alone could not fix:
- next 14/15.3 -> 15.5.18 (docs + apps/dev/nextjs)
- svelte 4 -> 5.55.7, @sveltejs/kit -> 2.60.1, devalue -> 5.8.1
(frameworks-sveltekit, apps/dev/sveltekit, sveltekit example)
- vitest 1.6.1 -> 3.2.6, vite 5 -> 6.4.2 (root + qwik/sveltekit apps)
- nodemailer 7 -> 8.0.5 (devDep) and widen peer to ^7.0.7 || ^8.0.0
(core, next-auth, frameworks-sveltekit)
- vite-plugin-static-copy -> 2.3.2 (frameworks-qwik)
- better-auth -> 1.6.16, shell-quote -> 1.8.4, @grpc/grpc-js -> 1.14.4,
brace-expansion -> 2.1.1, mailparser -> 3.9.3,
estree-util-value-to-estree -> 3.3.3 (root overrides)
- undici -> ^6.24.0 (qwik apps), @actions/core -> 1.11.1, qs -> 6.15.2
(broken-link-checker)
- example lockfile refreshes (qwik, sveltekit, express, solid-start)
Resolves 167 of 200 open Dependabot alerts. The remainder are pinned
by upstream majors (tar@6 via node-gyp chain, undici@5 via miniflare 2,
old AWS/Azure/GCP SDK transitives, archived solid-start) and will be
dismissed with comments.
* chore(deps): fix additional alerts (jsonwebtoken, socks/ip, micromatch, cross-spawn, vue-template-compiler, tsup)
- override jsonwebtoken@8 -> 9.0.0 (legacy @azure/msal-node chain)
- override socks@2 -> 2.8.9, eliminating abandoned 'ip' package
- override micromatch@4 -> 4.0.8, cross-spawn@5 -> 6.0.6
- vite-plugin-dts 3 -> 4 in frameworks-qwik (drops vue-template-compiler)
- tsup -> 8.5.1 in broken-link-checker1 parent d008b9b commit a99514b
22 files changed
Lines changed: 5000 additions & 8041 deletions
File tree
- .github/broken-link-checker
- apps
- dev
- nextjs
- qwik
- sveltekit
- examples
- express
- qwik
- solid-start
- sveltekit
- docs
- packages
- core
- frameworks-qwik
- frameworks-sveltekit
- next-auth
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
22 | | - | |
| 22 | + | |
23 | 23 | | |
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
27 | | - | |
| 27 | + | |
28 | 28 | | |
29 | 29 | | |
30 | 30 | | |
| |||
40 | 40 | | |
41 | 41 | | |
42 | 42 | | |
43 | | - | |
| 43 | + | |
44 | 44 | | |
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
48 | 48 | | |
49 | | - | |
| 49 | + | |
50 | 50 | | |
51 | 51 | | |
52 | 52 | | |
| |||
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
| 4 | + | |
4 | 5 | | |
5 | 6 | | |
6 | 7 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
14 | | - | |
| 14 | + | |
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
37 | 37 | | |
38 | 38 | | |
39 | 39 | | |
40 | | - | |
41 | | - | |
| 40 | + | |
| 41 | + | |
42 | 42 | | |
43 | 43 | | |
44 | 44 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | | - | |
16 | | - | |
17 | | - | |
18 | | - | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
22 | | - | |
23 | | - | |
24 | | - | |
25 | | - | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
26 | 26 | | |
27 | 27 | | |
28 | | - | |
29 | | - | |
30 | | - | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
31 | 31 | | |
32 | | - | |
| 32 | + | |
33 | 33 | | |
34 | 34 | | |
35 | 35 | | |
| |||
41 | 41 | | |
42 | 42 | | |
43 | 43 | | |
44 | | - | |
| 44 | + | |
| 45 | + | |
45 | 46 | | |
46 | 47 | | |
47 | 48 | | |
0 commit comments