mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
Resolve the actionable Dependabot alerts via pnpm overrides (for transitive deps) and a Python pin bump. - pnpm overrides: esbuild >=0.28.1 (the lone high-severity alert), @babel/core >=7.29.6, @opentelemetry/core >=2.8.0, js-yaml >=4.2.0, qs >=6.15.2, uuid >=11.1.1, yaml >=2.8.3 - rembg 2.0.62 -> 2.0.75 in requirements.txt and requirements-gpu.txt Verified: pnpm install, typecheck, lint, and full build all pass. NOT included: the astro advisory requires Astro 5 -> 6 (a major, breaking framework upgrade), which warrants its own migration PR rather than a security bump.
11 lines
224 B
Plaintext
11 lines
224 B
Plaintext
rembg[cpu]==2.0.75
|
|
realesrgan==0.3.0
|
|
paddleocr[doc-parser]>=3.4.0,<3.5.0
|
|
paddlepaddle>=3.0.0,<3.1.0
|
|
mediapipe>=0.10.21
|
|
onnxruntime==1.20.1
|
|
numpy==1.26.4
|
|
Pillow==12.2.0
|
|
opencv-python-headless==4.10.0.84
|
|
codeformer-pip==0.0.4
|