mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
fix(security): resolve 13 HIGH Trivy CVEs in npm dependencies
- Override glob>=10.5.0 (CVE-2025-64756 command injection) - Override minimatch>=9.0.6 (CVE-2026-26996/27903/27904 ReDoS) - Override tar>=7.5.11 (CVE-2026-23745/23950/24842/26960/29786/31802 path traversal and arbitrary file overwrite) - picomatch>=4.0.4 already overridden (CVE-2026-33671 ReDoS) - Add .trivyignore for pnpm 9.x CVEs (CVE-2025-69262/69263) that require a major version bump to pnpm 10.x - Restore Trivy as a blocking gate with trivyignore support - Restore scan dependency in manifest job
This commit is contained in:
@@ -81,7 +81,10 @@
|
||||
"overrides": {
|
||||
"fast-uri": ">=3.1.2",
|
||||
"handlebars": ">=4.7.9",
|
||||
"glob": ">=10.5.0",
|
||||
"minimatch": ">=9.0.6",
|
||||
"picomatch": ">=4.0.4",
|
||||
"tar": ">=7.5.11",
|
||||
"lodash": ">=4.18.0",
|
||||
"lodash-es": ">=4.18.0",
|
||||
"brace-expansion>minimatch": "^2.0.2",
|
||||
|
||||
Reference in New Issue
Block a user