From 3bb0138d1a797be7adb04db11b61a5fd6b5b8fc1 Mon Sep 17 00:00:00 2001 From: Dan Grebb Date: Sat, 27 Jan 2024 21:17:12 -0500 Subject: [PATCH] chore(back): override vite@<5.0.12 with vite@>=5.0.12 GHSA-c24v-8rfc-w8vw https://github.com/dgrebb/dgrebb.com/security/dependabot/50 --- back/package.json | 8 ++++++++ back/pnpm-lock.yaml | 21 ++++++++++++--------- 2 files changed, 20 insertions(+), 9 deletions(-) diff --git a/back/package.json b/back/package.json index 91e81586c..0360f7ed2 100644 --- a/back/package.json +++ b/back/package.json @@ -37,5 +37,13 @@ "strapi": {}, "devDependencies": { "prop-types": "^15.8.1" + }, + "overrides": { + "vite": "^4.5.2" + }, + "pnpm": { + "overrides": { + "vite@<5.0.12": ">=5.0.12" + } } } diff --git a/back/pnpm-lock.yaml b/back/pnpm-lock.yaml index 19e6baed5..ff8c7b6cd 100644 --- a/back/pnpm-lock.yaml +++ b/back/pnpm-lock.yaml @@ -4,6 +4,9 @@ settings: autoInstallPeers: true excludeLinksFromLockfile: false +overrides: + vite@<5.0.12: '>=5.0.12' + dependencies: '@strapi/plugin-color-picker': specifier: 4.19.0 @@ -3132,7 +3135,7 @@ packages: '@strapi/types': 4.19.0(pg@8.11.3) '@strapi/typescript-utils': 4.19.0 '@strapi/utils': 4.19.0 - '@vitejs/plugin-react-swc': 3.5.0(vite@5.0.11) + '@vitejs/plugin-react-swc': 3.5.0(vite@5.0.12) axios: 1.6.0(debug@4.3.4) bcryptjs: 2.4.3 boxen: 5.1.2 @@ -3217,7 +3220,7 @@ packages: styled-components: 5.3.3(@babel/core@7.23.7)(react-dom@18.2.0)(react-is@18.2.0)(react@18.2.0) typescript: 5.2.2 use-context-selector: 1.4.1(react-dom@18.2.0)(react@18.2.0)(scheduler@0.23.0) - vite: 5.0.11 + vite: 5.0.12 webpack: 5.89.0(esbuild@0.19.11) webpack-bundle-analyzer: 4.10.1 webpack-dev-middleware: 6.1.1(webpack@5.89.0) @@ -3600,7 +3603,7 @@ packages: engines: {node: '>=18.0.0 <=20.x.x', npm: '>=6.0.0'} hasBin: true dependencies: - '@vitejs/plugin-react-swc': 3.5.0(vite@5.0.11) + '@vitejs/plugin-react-swc': 3.5.0(vite@5.0.12) boxen: 5.1.2 browserslist-to-esbuild: 1.2.0 chalk: 4.1.2 @@ -3619,7 +3622,7 @@ packages: prompts: 2.4.2 rxjs: 7.8.1 typescript: 5.2.2 - vite: 5.0.11 + vite: 5.0.12 yup: 0.32.9 transitivePeerDependencies: - '@swc/helpers' @@ -4668,13 +4671,13 @@ packages: resolution: {integrity: sha512-zuVdFrMJiuCDQUMCzQaD6KL28MjnqqN8XnAqiEq9PNm/hCPTSGfrXCOfwj1ow4LFb/tNymJPwsNbVePc1xFqrQ==} dev: false - /@vitejs/plugin-react-swc@3.5.0(vite@5.0.11): + /@vitejs/plugin-react-swc@3.5.0(vite@5.0.12): resolution: {integrity: sha512-1PrOvAaDpqlCV+Up8RkAh9qaiUjoDUcjtttyhXDKw53XA6Ve16SOp6cCOpRs8Dj8DqUQs6eTW5YkLcLJjrXAig==} peerDependencies: - vite: ^4 || ^5 + vite: '>=5.0.12' dependencies: '@swc/core': 1.3.106 - vite: 5.0.11 + vite: 5.0.12 transitivePeerDependencies: - '@swc/helpers' dev: false @@ -12092,8 +12095,8 @@ packages: engines: {node: '>= 0.8'} dev: false - /vite@5.0.11: - resolution: {integrity: sha512-XBMnDjZcNAw/G1gEiskiM1v6yzM4GE5aMGvhWTlHAYYhxb7S3/V1s3m2LDHa8Vh6yIWYYB0iJwsEaS523c4oYA==} + /vite@5.0.12: + resolution: {integrity: sha512-4hsnEkG3q0N4Tzf1+t6NdN9dg/L3BM+q8SWgbSPnJvrgH2kgdyzfVJwbR1ic69/4uMJJ/3dqDZZE5/WwqW8U1w==} engines: {node: ^18.0.0 || >=20.0.0} hasBin: true peerDependencies: