Skip to content

Commit a99514b

Browse files
authored
chore(deps): resolve remaining Dependabot alerts via cross-major dependency upgrades (#13449)
* chore(deps): resolve remaining Dependabot alerts via dependency upgrades Cross-major security upgrades that pnpm overrides alone could not fix: - next 14/15.3 -> 15.5.18 (docs + apps/dev/nextjs) - svelte 4 -> 5.55.7, @sveltejs/kit -> 2.60.1, devalue -> 5.8.1 (frameworks-sveltekit, apps/dev/sveltekit, sveltekit example) - vitest 1.6.1 -> 3.2.6, vite 5 -> 6.4.2 (root + qwik/sveltekit apps) - nodemailer 7 -> 8.0.5 (devDep) and widen peer to ^7.0.7 || ^8.0.0 (core, next-auth, frameworks-sveltekit) - vite-plugin-static-copy -> 2.3.2 (frameworks-qwik) - better-auth -> 1.6.16, shell-quote -> 1.8.4, @grpc/grpc-js -> 1.14.4, brace-expansion -> 2.1.1, mailparser -> 3.9.3, estree-util-value-to-estree -> 3.3.3 (root overrides) - undici -> ^6.24.0 (qwik apps), @actions/core -> 1.11.1, qs -> 6.15.2 (broken-link-checker) - example lockfile refreshes (qwik, sveltekit, express, solid-start) Resolves 167 of 200 open Dependabot alerts. The remainder are pinned by upstream majors (tar@6 via node-gyp chain, undici@5 via miniflare 2, old AWS/Azure/GCP SDK transitives, archived solid-start) and will be dismissed with comments. * chore(deps): fix additional alerts (jsonwebtoken, socks/ip, micromatch, cross-spawn, vue-template-compiler, tsup) - override jsonwebtoken@8 -> 9.0.0 (legacy @azure/msal-node chain) - override socks@2 -> 2.8.9, eliminating abandoned 'ip' package - override micromatch@4 -> 4.0.8, cross-spawn@5 -> 6.0.6 - vite-plugin-dts 3 -> 4 in frameworks-qwik (drops vue-template-compiler) - tsup -> 8.5.1 in broken-link-checker
1 parent d008b9b commit a99514b

22 files changed

Lines changed: 5000 additions & 8041 deletions

File tree

.github/broken-link-checker/package.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -19,12 +19,12 @@
1919
"license": "MIT",
2020
"devDependencies": {
2121
"@types/node": "^20.11.15",
22-
"tsup": "^8.0.1",
22+
"tsup": "^8.5.1",
2323
"tsx": "^4.7.0",
2424
"typescript": "^5.3.3"
2525
},
2626
"dependencies": {
27-
"@actions/core": "^1.10.1",
27+
"@actions/core": "^1.11.1",
2828
"@actions/github": "^6.0.0",
2929
"broken-link-checker": "^0.7.8"
3030
},
@@ -40,13 +40,13 @@
4040
"glob@10": "10.5.0",
4141
"minimatch@9": "9.0.7",
4242
"picomatch@2": "2.3.2",
43-
"qs@6": "6.14.1",
43+
"qs@6": "6.15.2",
4444
"robots-txt-guard@1": "1.0.2",
4545
"rollup@4": "4.59.0",
4646
"semver@5": "5.7.2",
4747
"tmp@0": "0.2.6",
4848
"tough-cookie@4": "4.1.3",
49-
"undici@5": "5.29.0",
49+
"undici@5": "6.24.0",
5050
"undici@6": "6.24.0",
5151
"uuid@11": "11.1.1"
5252
}

.github/broken-link-checker/pnpm-lock.yaml

Lines changed: 184 additions & 394 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

apps/dev/nextjs/next-env.d.ts

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
/// <reference types="next" />
22
/// <reference types="next/image-types/global" />
33
/// <reference types="next/navigation-types/compat/navigation" />
4+
/// <reference path="./.next/types/routes.d.ts" />
45

56
// NOTE: This file should not be edited
67
// see https://nextjs.org/docs/app/api-reference/config/typescript for more information.

apps/dev/nextjs/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@
1111
},
1212
"license": "ISC",
1313
"dependencies": {
14-
"next": "15.3.1",
14+
"next": "15.5.18",
1515
"next-auth": "workspace:*",
1616
"react": "19.0.0-rc-4c58fce7-20240904",
1717
"react-dom": "19.0.0-rc-4c58fce7-20240904"

apps/dev/qwik/package.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -37,8 +37,8 @@
3737
"eslint-plugin-qwik": "^1.5.5",
3838
"prettier": "^3.2.5",
3939
"typescript": "5.4.5",
40-
"undici": "*",
41-
"vite": "^5.2.10",
40+
"undici": "^6.24.0",
41+
"vite": "^6.4.2",
4242
"vite-tsconfig-paths": "^4.2.1"
4343
}
4444
}

apps/dev/sveltekit/package.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -12,10 +12,10 @@
1212
},
1313
"devDependencies": {
1414
"@sveltejs/adapter-auto": "next",
15-
"@sveltejs/kit": "^2.5.7",
16-
"@sveltejs/vite-plugin-svelte": "^3.0.0",
17-
"svelte": "^4",
18-
"svelte-check": "2.10.2",
15+
"@sveltejs/kit": "^2.60.1",
16+
"@sveltejs/vite-plugin-svelte": "^5.1.1",
17+
"svelte": "^5.55.7",
18+
"svelte-check": "^4.0.4",
1919
"typescript": "5.2.2"
2020
},
2121
"dependencies": {

apps/examples/express/package.json

Lines changed: 10 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -19,17 +19,17 @@
1919
"license": "ISC",
2020
"dependencies": {
2121
"@auth/express": "latest",
22-
"express": "^4.19.2",
23-
"morgan": "^1.10.0",
24-
"pug": "^3.0.2",
25-
"tailwindcss": "^3.4.3"
22+
"express": "^4.22.2",
23+
"morgan": "^1.11.0",
24+
"pug": "^3.0.4",
25+
"tailwindcss": "^3.4.19"
2626
},
2727
"devDependencies": {
28-
"@types/express": "^4.17.21",
29-
"@types/morgan": "^1.9.9",
30-
"@types/node": "^20.12.7",
28+
"@types/express": "^4.17.25",
29+
"@types/morgan": "^1.9.10",
30+
"@types/node": "^20.19.43",
3131
"@types/pug": "^2.0.10",
32-
"tsx": "^4.7.0",
32+
"tsx": "^4.22.4",
3333
"typescript": "5.3.3"
3434
},
3535
"pnpm": {
@@ -41,7 +41,8 @@
4141
"path-to-regexp@0": "0.1.13",
4242
"picomatch@2": "2.3.2",
4343
"qs@6": "6.15.2",
44-
"yaml@2": "2.8.3"
44+
"yaml@2": "2.8.3",
45+
"postcss@8": "8.5.10"
4546
}
4647
}
4748
}

0 commit comments

Comments
 (0)