diff --git a/.github/workflows/prepare-release.yml b/.github/workflows/prepare-release.yml index fa3a77df..346c0525 100644 --- a/.github/workflows/prepare-release.yml +++ b/.github/workflows/prepare-release.yml @@ -120,20 +120,54 @@ jobs: if grep -q "^## \[${VERSION_NO_V}\]" CHANGELOG.md 2>/dev/null; then echo "changelog_exists=true" >> "$GITHUB_OUTPUT" + echo "from_unreleased=false" >> "$GITHUB_OUTPUT" echo "Changelog section for [${VERSION_NO_V}] already exists. Skipping generation." exit 0 fi - echo "changelog_exists=false" >> "$GITHUB_OUTPUT" + # Prefer a curated [Unreleased] section when present: promote it to the release version + # instead of generating entries from the commit history. + FROM_UNRELEASED=false + if grep -q "^## \[Unreleased\]" CHANGELOG.md 2>/dev/null; then + FROM_UNRELEASED=true + echo "changelog_exists=true" >> "$GITHUB_OUTPUT" + echo "from_unreleased=true" >> "$GITHUB_OUTPUT" + echo "Found [Unreleased] section. Promoting it to [${VERSION_NO_V}]." + else + echo "changelog_exists=false" >> "$GITHUB_OUTPUT" + echo "from_unreleased=false" >> "$GITHUB_OUTPUT" + fi + export FROM_UNRELEASED export COMMITS=$(git log ${COMMIT_RANGE} --format='%s' --no-merges) export VERSION_NO_V="${{ steps.validate.outputs.version_no_v }}" node << 'SCRIPT' const fs = require('fs'); - const commits = process.env.COMMITS.split('\n').filter(Boolean); const version = process.env.VERSION_NO_V; const today = new Date().toISOString().split('T')[0]; + const fromUnreleased = process.env.FROM_UNRELEASED === 'true'; + + const changelog = fs.readFileSync('CHANGELOG.md', 'utf8'); + + // Promotion path: turn the curated [Unreleased] section into the new release section, + // assigning it the release version and date while preserving all of its entries. + if (fromUnreleased) { + const unreleasedHeading = /^## \[Unreleased\].*$/m; + if (!unreleasedHeading.test(changelog)) { + console.error('::error::from_unreleased was set but no [Unreleased] section was found.'); + process.exit(1); + } + + const releaseHeading = `## [${version}] - ${today}`; + const updated = changelog.replace(unreleasedHeading, releaseHeading); + fs.writeFileSync('CHANGELOG.md', updated.endsWith('\n') ? updated : `${updated}\n`); + console.log('Promoted [Unreleased] section to ' + releaseHeading); + process.exit(0); + } + + // Fallback path: generate a release section from conventional commits. + const commits = process.env.COMMITS.split('\n').filter(Boolean); const sections = { added: [], @@ -192,7 +226,6 @@ jobs: } } - const changelog = fs.readFileSync('CHANGELOG.md', 'utf8'); const lines = changelog.split('\n'); const header = lines.slice(0, 6).join('\n'); const body = lines.slice(6).join('\n'); @@ -275,6 +308,7 @@ jobs: run: | PREV_TAG="${{ steps.changelog.outputs.prev_tag }}" CHANGELOG_EXISTS="${{ steps.changelog.outputs.changelog_exists }}" + FROM_UNRELEASED="${{ steps.changelog.outputs.from_unreleased }}" BODY=$(cat << EOF ## Release Preparation @@ -284,7 +318,7 @@ jobs: ### Changes Included - Version bump to \`${VERSION_NO_V}\` in all package.json files - - Changelog update $(if [[ "${CHANGELOG_EXISTS}" == "true" ]]; then echo "(existing entry preserved)"; else echo "(auto-generated)"; fi) + - Changelog update $(if [[ "${FROM_UNRELEASED}" == "true" ]]; then echo "(promoted from [Unreleased])"; elif [[ "${CHANGELOG_EXISTS}" == "true" ]]; then echo "(existing entry preserved)"; else echo "(auto-generated)"; fi) ### Review Checklist diff --git a/CHANGELOG.md b/CHANGELOG.md index 923dbbc2..52c62f19 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,33 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). +## [Unreleased] + +### Security + +- Remediate **high**- and **moderate**-severity dependency vulnerabilities + (8 findings: 2 high, 6 moderate): + - `nodemailer` 9.0.1 → 9.1.1 — **direct production dependency**. Fixes a quadratic (O(n²)) time + complexity in `addressparser` that allows a remote denial of service via a crafted address list + ([GHSA-2x7j-588g-ccc2](https://github.com/advisories/GHSA-2x7j-588g-ccc2)), a bypass of + `disableFileAccess`/`disableUrlAccess` when `resolveContent()` is called on a `MailMessage` with + the legacy signature ([GHSA-8m3c-c648-2xjj](https://github.com/advisories/GHSA-8m3c-c648-2xjj)), + an IDN/Punycode domain allow-list bypass that delivers mail to an attacker-controlled domain + ([GHSA-wmmp-3585-3rmp](https://github.com/advisories/GHSA-wmmp-3585-3rmp)), and a + recipient-domain validation bypass via RFC 5322 comment mis-parsing + ([GHSA-cc9r-2j5m-2m83](https://github.com/advisories/GHSA-cc9r-2j5m-2m83)) + - `js-yaml` 4.3.1 → 4.3.2 — fixes `maxTotalMergeKeys` not limiting CPU use for empty merge sources + ([GHSA-2883-xcg3-v3hh](https://github.com/advisories/GHSA-2883-xcg3-v3hh)), on top of the + previously pinned `!!omap` quadratic CPU consumption fix (GHSA-52cp-r559-cp3m). It is pulled by + `cosmiconfig` through the commitlint and stylelint toolchains + - `colord` 2.9.3 → 2.10.0 — fixes slow rejection of oversized malformed color strings + ([GHSA-2wm5-q62r-hmrv](https://github.com/advisories/GHSA-2wm5-q62r-hmrv)). It is pulled by + `stylelint` + - `vitest` and `@vitest/mocker` 4.1.10 → 4.1.11 — fixes path traversal / arbitrary file read via + the `@vitest/mocker` redirect mock + ([GHSA-82fw-gwwq-j7x9](https://github.com/advisories/GHSA-82fw-gwwq-j7x9)). `@vitest/coverage-v8` + and `@vitest/ui` are bumped alongside to keep the Vitest family aligned + ## [3.0.1] - 2026-09-05 ### Security diff --git a/THIRD-PARTY-NOTICES.md b/THIRD-PARTY-NOTICES.md index 860e839b..0a1a114d 100644 --- a/THIRD-PARTY-NOTICES.md +++ b/THIRD-PARTY-NOTICES.md @@ -4,7 +4,7 @@ This document contains the license information for third-party packages used in **Project:** Scrumooth - Agile Scrum Lifecycle Management System **License:** Apache-2.0 -**Last Updated:** August 16, 2026 +**Last Updated:** September 13, 2026 --- @@ -31,7 +31,7 @@ This document contains the license information for third-party packages used in | @prisma/adapter-pg | 7.9.1 | Apache-2.0 | Prisma Data, Inc. | https://github.com/prisma/prisma | | @prisma/client | 7.9.1 | Apache-2.0 | Prisma Data, Inc. | https://github.com/prisma/prisma | | bcrypt | 6.0.0 | MIT | Nick Campbell | https://github.com/kelektiv/node.bcrypt.js | -| compression | 1.8.1 | MIT | Jonathan Ong | https://github.com/expressjs/compression | +| compression | 1.8.2 | MIT | Jonathan Ong | https://github.com/expressjs/compression | | cookie-parser | 1.4.7 | MIT | TJ Holowaychuk | https://github.com/expressjs/cookie-parser | | cors | 2.8.6 | MIT | Troy Goode | https://github.com/expressjs/cors | | dotenv | 17.4.2 | BSD-2-Clause | Scott Motte | https://github.com/motdotla/dotenv | @@ -42,7 +42,7 @@ This document contains the license information for third-party packages used in | intl-pluralrules | 2.0.1 | ISC | Eemeli Aro | https://github.com/eemeli/intl-pluralrules | | jsonwebtoken | 9.0.3 | MIT | Auth0, Inc. | https://github.com/auth0/node-jsonwebtoken | | node-cron | 4.6.0 | MIT | Lucas Merencia | https://github.com/merencia/node-cron | -| nodemailer | 9.0.5 | MIT | Andris Reinman | https://github.com/nodemailer/nodemailer | +| nodemailer | 9.1.1 | MIT-0 | Andris Reinman | https://github.com/nodemailer/nodemailer | | resolve-accept-language | 3.2.2 | MIT | Nicolas Bouvrette | https://github.com/resolve-accept-language/resolve-accept-language | | sanitize-html | 2.17.7 | MIT | Apostrophe Technologies, Inc. | https://github.com/apostrophecms/sanitize-html | | uuid | 14.0.1 | MIT | uuidjs | https://github.com/uuidjs/uuid | @@ -71,7 +71,7 @@ This document contains the license information for third-party packages used in | @types/supertest | 7.2.1 | MIT | DefinitelyTyped | https://github.com/DefinitelyTyped/DefinitelyTyped | | @typescript-eslint/eslint-plugin | 8.67.0 | MIT | TypeScript ESLint | https://github.com/typescript-eslint/typescript-eslint | | @typescript-eslint/parser | 8.67.0 | MIT | TypeScript ESLint | https://github.com/typescript-eslint/typescript-eslint | -| @vitest/coverage-v8 | 4.1.10 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest | +| @vitest/coverage-v8 | 4.1.11 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest | | cross-env | 10.1.0 | MIT | Kent C. Dodds | https://github.com/kentcdodds/cross-env | | eslint | 10.8.1 | MIT | OpenJS Foundation | https://github.com/eslint/eslint | | eslint-config-prettier | 10.1.8 | MIT | Simon Lydell | https://github.com/prettier/eslint-config-prettier | @@ -83,7 +83,7 @@ This document contains the license information for third-party packages used in | supertest | 7.2.2 | MIT | TJ Holowaychuk | https://github.com/ladjs/supertest | | tsx | 4.23.12 | MIT | Hiroki Osame | https://github.com/privatenumber/tsx | | typescript | 6.0.3 | Apache-2.0 | Microsoft Corporation | https://github.com/microsoft/TypeScript | -| vitest | 4.1.10 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest | +| vitest | 4.1.11 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest | --- @@ -126,8 +126,8 @@ This document contains the license information for third-party packages used in | @types/react | 19.2.18 | MIT | DefinitelyTyped | https://github.com/DefinitelyTyped/DefinitelyTyped | | @types/react-dom | 19.2.4 | MIT | DefinitelyTyped | https://github.com/DefinitelyTyped/DefinitelyTyped | | @vitejs/plugin-react | 6.0.5 | MIT | Vite | https://github.com/vitejs/vite-plugin-react | -| @vitest/coverage-v8 | 4.1.10 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest | -| @vitest/ui | 4.1.10 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest | +| @vitest/coverage-v8 | 4.1.11 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest | +| @vitest/ui | 4.1.11 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest | | cross-env | 10.1.0 | MIT | Kent C. Dodds | https://github.com/kentcdodds/cross-env | | eslint | 10.8.1 | MIT | OpenJS Foundation | https://github.com/eslint/eslint | | eslint-config-prettier | 10.1.8 | MIT | Simon Lydell | https://github.com/prettier/eslint-config-prettier | @@ -145,7 +145,7 @@ This document contains the license information for third-party packages used in | typescript-eslint | 8.67.0 | MIT | TypeScript ESLint | https://github.com/typescript-eslint/typescript-eslint | | vi-axe | 1.0.0 | MIT | Chan Zuckerberg Initiative | https://github.com/chanzuckerberg/vi-axe | | vite | 8.2.1 | MIT | Vite | https://github.com/vitejs/vite | -| vitest | 4.1.10 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest | +| vitest | 4.1.11 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest | --- @@ -178,7 +178,7 @@ This document contains the license information for third-party packages used in | stylelint-no-unsupported-browser-features | 8.1.1 | MIT | Cédric Delpoux | https://github.com/RJWadley/stylelint-no-unsupported-browser-features | | typescript | 6.0.3 | Apache-2.0 | Microsoft Corporation | https://github.com/microsoft/TypeScript | | typescript-eslint | 8.67.0 | MIT | TypeScript ESLint | https://github.com/typescript-eslint/typescript-eslint | -| vitest | 4.1.10 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest | +| vitest | 4.1.11 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest | --- @@ -188,7 +188,7 @@ This document contains the license information for third-party packages used in | ---------------------- | ------- | ------------ | ---------------------- | -------------------------------------------------- | | @eslint/js | 10.0.1 | MIT | OpenJS Foundation | https://github.com/eslint/eslint | | @types/node | 24.13.3 | MIT | DefinitelyTyped | https://github.com/DefinitelyTyped/DefinitelyTyped | -| @vitest/coverage-v8 | 4.1.10 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest | +| @vitest/coverage-v8 | 4.1.11 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest | | date-fns | 4.4.0 | MIT | Sasha Koss, Lesha Koss | https://github.com/date-fns/date-fns | | eslint | 10.8.1 | MIT | OpenJS Foundation | https://github.com/eslint/eslint | | eslint-config-prettier | 10.1.8 | MIT | Simon Lydell | https://github.com/prettier/eslint-config-prettier | @@ -196,7 +196,7 @@ This document contains the license information for third-party packages used in | prettier | 3.9.6 | MIT | Prettier | https://github.com/prettier/prettier | | rimraf | 6.1.3 | MIT | Isaac Z. Schlueter | https://github.com/isaacs/rimraf | | typescript | 6.0.3 | Apache-2.0 | Microsoft Corporation | https://github.com/microsoft/TypeScript | -| vitest | 4.1.10 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest | +| vitest | 4.1.11 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest | --- @@ -254,6 +254,29 @@ OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. ``` +### MIT No Attribution License (MIT-0) + +Used by `nodemailer`. + +``` +MIT No Attribution + +Copyright + +Permission is hereby granted, free of charge, to any person obtaining a copy of this +software and associated documentation files (the "Software"), to deal in the Software +without restriction, including without limitation the rights to use, copy, modify, +merge, publish, distribute, sublicense, and/or sell copies of the Software, and to +permit persons to whom the Software is furnished to do so. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, +INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A +PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT +HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF +CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE +OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. +``` + ### Apache License 2.0 ``` @@ -450,10 +473,11 @@ OTHER DEALINGS IN THE FONT SOFTWARE. | License Type | Package Count | Percentage | | ------------------ | ------------- | ---------- | -| MIT | 125 | 89.3% | +| MIT | 124 | 88.6% | | Apache-2.0 | 9 | 6.4% | | ISC | 2 | 1.4% | | BSD-2-Clause | 2 | 1.4% | +| MIT-0 | 1 | 0.7% | | OFL-1.1 | 1 | 0.7% | | PostgreSQL License | 1 | 0.7% | @@ -463,7 +487,7 @@ OTHER DEALINGS IN THE FONT SOFTWARE. ## Compliance Statement -All dependencies listed in this document use OSI-approved open-source licenses that are compatible with the Apache-2.0 license under which Scrumooth is distributed. No copyleft licenses (GPL, LGPL, AGPL) are present in the dependency tree. The bundled Inter font is distributed under the SIL Open Font License 1.1, which permits bundling and redistribution with software and is compatible with Apache-2.0. The PostgreSQL server is distributed under the permissive PostgreSQL License, and nginx under the BSD-2-Clause license, both compatible with Apache-2.0. +All dependencies listed in this document use OSI-approved open-source licenses that are compatible with the Apache-2.0 license under which Scrumooth is distributed. No copyleft licenses (GPL, LGPL, AGPL) are present in the dependency tree. `MIT-0` (MIT No Attribution), used by `nodemailer`, is the permissive MIT license with the attribution clause removed; it is OSI-approved and adds no obligations beyond those of MIT. The bundled Inter font is distributed under the SIL Open Font License 1.1, which permits bundling and redistribution with software and is compatible with Apache-2.0. The PostgreSQL server is distributed under the permissive PostgreSQL License, and nginx under the BSD-2-Clause license, both compatible with Apache-2.0. ### Transitive Dependencies @@ -492,5 +516,5 @@ This document should be updated whenever: --- -**Document Version:** 3.0 -**Generated:** August 16, 2026 +**Document Version:** 3.1 +**Generated:** September 13, 2026 diff --git a/packages/backend/package.json b/packages/backend/package.json index 61953f1c..6062e8dd 100644 --- a/packages/backend/package.json +++ b/packages/backend/package.json @@ -76,7 +76,7 @@ "intl-pluralrules": "catalog:", "jsonwebtoken": "^9.0.3", "node-cron": "^4.2.1", - "nodemailer": "^9.0.1", + "nodemailer": "^9.1.1", "resolve-accept-language": "^3.2.2", "sanitize-html": "^2.17.5", "uuid": "^14.0.0", diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 43701742..449669c2 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -13,11 +13,11 @@ catalogs: specifier: ^24.13.3 version: 24.13.3 '@vitest/coverage-v8': - specifier: ^4.1.10 - version: 4.1.10 + specifier: ^4.1.11 + version: 4.1.11 '@vitest/ui': - specifier: ^4.1.10 - version: 4.1.10 + specifier: ^4.1.11 + version: 4.1.11 cross-env: specifier: ^10.1.0 version: 10.1.0 @@ -70,8 +70,8 @@ catalogs: specifier: ^8.67.0 version: 8.67.0 vitest: - specifier: ^4.1.10 - version: 4.1.10 + specifier: ^4.1.11 + version: 4.1.11 overrides: brace-expansion: ^5.0.9 @@ -83,7 +83,8 @@ overrides: fast-uri: ^3.1.6 form-data: ^4.0.6 hono: ^4.12.34 - js-yaml: ^4.3.1 + js-yaml: ^4.3.2 + colord: ^2.9.4 nanoid: ^3.3.17 shell-quote: ^1.8.5 body-parser: ^2.3.0 @@ -169,7 +170,7 @@ importers: version: 8.67.0(eslint@10.8.1(jiti@2.7.0)(supports-color@10.2.2))(supports-color@10.2.2)(typescript@6.0.3) vitest: specifier: 'catalog:' - version: 4.1.10(@types/node@26.2.0)(@vitest/coverage-v8@4.1.10)(@vitest/ui@4.1.10)(jsdom@29.1.1)(vite@8.2.1(@types/node@26.2.0)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0)) + version: 4.1.11(@types/node@26.2.0)(@vitest/coverage-v8@4.1.11)(@vitest/ui@4.1.11)(jsdom@29.1.1)(vite@8.2.1(@types/node@26.2.0)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0)) packages/backend: dependencies: @@ -187,7 +188,7 @@ importers: version: 6.0.0 compression: specifier: ^1.8.1 - version: 1.8.1(supports-color@10.2.2) + version: 1.8.2(supports-color@10.2.2) cookie-parser: specifier: ^1.4.7 version: 1.4.7 @@ -219,8 +220,8 @@ importers: specifier: ^4.2.1 version: 4.6.0 nodemailer: - specifier: ^9.0.1 - version: 9.0.5 + specifier: ^9.1.1 + version: 9.1.1 resolve-accept-language: specifier: ^3.2.2 version: 3.2.2 @@ -281,7 +282,7 @@ importers: version: 7.2.1 '@vitest/coverage-v8': specifier: 'catalog:' - version: 4.1.10(vitest@4.1.10) + version: 4.1.11(vitest@4.1.11) cross-env: specifier: 'catalog:' version: 10.1.0 @@ -314,7 +315,7 @@ importers: version: 6.0.3 vitest: specifier: 'catalog:' - version: 4.1.10(@types/node@24.13.3)(@vitest/coverage-v8@4.1.10)(@vitest/ui@4.1.10)(jsdom@29.1.1)(vite@8.2.1(@types/node@24.13.3)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0)) + version: 4.1.11(@types/node@24.13.3)(@vitest/coverage-v8@4.1.11)(@vitest/ui@4.1.11)(jsdom@29.1.1)(vite@8.2.1(@types/node@24.13.3)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0)) packages/frontend: dependencies: @@ -408,10 +409,10 @@ importers: version: 6.0.5(vite@8.2.1(@types/node@24.13.3)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0)) '@vitest/coverage-v8': specifier: 'catalog:' - version: 4.1.10(vitest@4.1.10) + version: 4.1.11(vitest@4.1.11) '@vitest/ui': specifier: 'catalog:' - version: 4.1.10(vitest@4.1.10) + version: 4.1.11(vitest@4.1.11) cross-env: specifier: 'catalog:' version: 10.1.0 @@ -465,7 +466,7 @@ importers: version: 8.2.1(@types/node@24.13.3)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0) vitest: specifier: 'catalog:' - version: 4.1.10(@types/node@24.13.3)(@vitest/coverage-v8@4.1.10)(@vitest/ui@4.1.10)(jsdom@29.1.1)(vite@8.2.1(@types/node@24.13.3)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0)) + version: 4.1.11(@types/node@24.13.3)(@vitest/coverage-v8@4.1.11)(@vitest/ui@4.1.11)(jsdom@29.1.1)(vite@8.2.1(@types/node@24.13.3)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0)) packages/shared: dependencies: @@ -481,7 +482,7 @@ importers: version: 24.13.3 '@vitest/coverage-v8': specifier: 'catalog:' - version: 4.1.10(vitest@4.1.10) + version: 4.1.11(vitest@4.1.11) eslint: specifier: 'catalog:' version: 10.8.1(jiti@2.7.0)(supports-color@10.2.2) @@ -502,7 +503,7 @@ importers: version: 6.0.3 vitest: specifier: 'catalog:' - version: 4.1.10(@types/node@24.13.3)(@vitest/coverage-v8@4.1.10)(@vitest/ui@4.1.10)(jsdom@29.1.1)(vite@8.2.1(@types/node@24.13.3)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0)) + version: 4.1.11(@types/node@24.13.3)(@vitest/coverage-v8@4.1.11)(@vitest/ui@4.1.11)(jsdom@29.1.1)(vite@8.2.1(@types/node@24.13.3)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0)) packages: @@ -1181,15 +1182,6 @@ packages: resolution: {integrity: sha512-R8gLRTZeyp03ymzP/6Lil/28tGeGEzhx1q2k703KGWRAI1VdvPIXdG70VJc2pAMw3NA6JKL5hhFu1sJX0Mnn/A==} engines: {node: '>=6.0.0'} - '@jridgewell/sourcemap-codec@1.4.10': - resolution: {integrity: sha512-Ht8wIW5v165atIX1p+JvKR5ONzUyF4Ac8DZIQ5kZs9zrb6M8SJNXpx1zn04rn65VjBMygRoMXcyYwNK0fT7bEg==} - - '@jridgewell/sourcemap-codec@1.5.0': - resolution: {integrity: sha512-gv3ZRaISU3fjPAgNsriBRqGWQL6quFx04YMPW/zD8XMLsU32mhCCbfbO6KZFLjvYpCZ8zyDEgqsgf+PwPaM7GQ==} - - '@jridgewell/sourcemap-codec@1.5.5': - resolution: {integrity: sha512-cYQ9310grqxueWbl+WuIUIaiUaDcj7WOq5fVhEljNVgRfOUhY9fy2zTvfoqWsnebh8Sl70VScFbICvJnLKB0Og==} - '@jridgewell/sourcemap-codec@1.6.0': resolution: {integrity: sha512-T7jf+5zgsZHwNJ4lvQ7/aezbyk0nNX+zJVWpmHA7VYsEx7a7qr5Rg5IbtJFqkgze5Y2sruq1RUY8Q837Od7iFw==} @@ -2053,20 +2045,20 @@ packages: babel-plugin-react-compiler: optional: true - '@vitest/coverage-v8@4.1.10': - resolution: {integrity: sha512-IM49HmthevbgAO4anp1hwtoT9wYe59w0LR00gr+eagHE+ZJ5lK4sLPeO0ubgoJcwLk6dehU3R24N+FbEEKDc8g==} + '@vitest/coverage-v8@4.1.11': + resolution: {integrity: sha512-8MVGEFnJIcdGjcbfKmeq8z0pZHH0JlVtoVZH9Q/qwUp6wyFnEJUBMrw9DCaj+ra3vShGmhavjalMIhPNxZAUcw==} peerDependencies: - '@vitest/browser': 4.1.10 - vitest: 4.1.10 + '@vitest/browser': 4.1.11 + vitest: 4.1.11 peerDependenciesMeta: '@vitest/browser': optional: true - '@vitest/expect@4.1.10': - resolution: {integrity: sha512-YsCn+qAk1GWjQOWFEsEcL2gNQ0zmVmQu3T03qP6UyjhtmdtwtbuI+DASn/7iQB3HGTXkdBwGddzxPlmiql5vlA==} + '@vitest/expect@4.1.11': + resolution: {integrity: sha512-VX2x5vNJXET47KAFzwERI+KRMtTTCSWTfSMKsW7JsUsXV4psq++e3DvZpuTDOpHcxytiDs6p2nhVb2tVDiiUYw==} - '@vitest/mocker@4.1.10': - resolution: {integrity: sha512-v0xaezt+DKEmKfaxg133ldzADrwLGd7Ze1MfQQTYfvs8OqZIwbxyxaYURivwV7sWy5fqn3rH5uOrSp07bp44Ow==} + '@vitest/mocker@4.1.11': + resolution: {integrity: sha512-2XJVD55d1o5AZous5CCGKS74g/riOj9odEt2bQpCVZeblHyHdnMeFl4jl0XjU21stf4mbjUkew2eXQZt65g5CQ==} peerDependencies: msw: ^2.4.9 vite: ^6.0.0 || ^7.0.0 || ^8.0.0 @@ -2076,25 +2068,25 @@ packages: vite: optional: true - '@vitest/pretty-format@4.1.10': - resolution: {integrity: sha512-W1HsjSH4MXQ9YfmmhLAoIYf1HRfekQCGngeIgcei6MP5QQGWUe0gkopdZQaVCFO+JDJMrAJGwa5pRpNpvy4P8Q==} + '@vitest/pretty-format@4.1.11': + resolution: {integrity: sha512-yiZzPbGTS9Sr/JpFl8zHrcIkAofNbFV6k21vIgQN/cY/oxZeXhJv5sc/MBJ5jFKWmWs+oJHw0UXLZjmf931+Vw==} - '@vitest/runner@4.1.10': - resolution: {integrity: sha512-IKI6kpIH+LmpROplyLwBBaCfMgOZOMsygVa6BARD6ahA04VRuJSa6OaVG7kRvSEMD870Vd91rSSw0eegtWyLGg==} + '@vitest/runner@4.1.11': + resolution: {integrity: sha512-LztvUgdwMNJMIkj3hQnnxiC2Xy1zNxq928W/xhjCLaNCzqTZOudjwbQf6v9IntZGPw132i2Lq2rgTRZHD3JHNw==} - '@vitest/snapshot@4.1.10': - resolution: {integrity: sha512-xRkfOT1qpTAi/Ti4Y1LtfRc3kEuqxGw59eN2jN9pRWMtS/XDevekhcFSqvQqjUNGksfjMJu3Y+oJ+4Ypn2OaJw==} + '@vitest/snapshot@4.1.11': + resolution: {integrity: sha512-pN7ikn1ON7h8ee4gIAp4AzyK+zBtJPzVbqOgu5LCEh4VaJVbPQcgYQYJIMGQPXVeJJq1fnfazis7a5pFNPahog==} - '@vitest/spy@4.1.10': - resolution: {integrity: sha512-PLf/Ugvoq5wO/b4rwYCR1h2PSIdXz7wnkQFMiUpLdtM7l6pqVFcQIBEHyT1+l+cj7mNwAfZHzqXqDyjvOuwbDw==} + '@vitest/spy@4.1.11': + resolution: {integrity: sha512-apNa/prQy2qCeywhnixOHPRCgGNhvg7T4Dapfl1GahLp/R+uhBm5cPyFoNVyqsNd2h1nJxL6BqqdIjiABL60YA==} - '@vitest/ui@4.1.10': - resolution: {integrity: sha512-EOUqfXHTXtpSHsyLHH40ts3Ue+hRhSGwzwzMlK0dTEOLSDYyOXLyr5JDGmHQWhN2DYI30gw6dVx3cdgM9FZl+Q==} + '@vitest/ui@4.1.11': + resolution: {integrity: sha512-r/rwyKoev21mWdRGSEkZOqkQ2BYy68mwjihg9M90nNRbf4NGrgzZ4cj6JNCEwlOGJkbKeMgsjlykvwKUbRr7gw==} peerDependencies: - vitest: 4.1.10 + vitest: 4.1.11 - '@vitest/utils@4.1.10': - resolution: {integrity: sha512-fy9am/HWxbaGt/Sawrp90vt6Y6jQwf1RX77cz3uwoJwJVMli/e1IEwRPnMNJ7vKfPTwo0diXifkpPvwH9v7nGA==} + '@vitest/utils@4.1.11': + resolution: {integrity: sha512-zTCVGpyFsGWBhllOyKlTw/vnr6D9qxsfSDyfbyZmTyjHw5N/VuvzHpHoQjm2ZJzn4RJgx5w4r7V0er69CmLgPQ==} accepts@2.0.0: resolution: {integrity: sha512-5cvg6CtKwfgdmVqY1WIiXKc3Q1bkRqGLi+2W/6ao+6Y7gu/RCwRuAhGEzh5B4KlszSuTLgZYuqFqo5bImjNKng==} @@ -2256,8 +2248,8 @@ packages: better-result@2.9.2: resolution: {integrity: sha512-WIFoBPCdnTOdk9inkE1ZRvCZ4P0CpSkAiLlchC65N7n9DcjZ3NhqkBOlafzpOVnO8ixyi37kicmSJ3ENhPZl7Q==} - bidi-js@1.0.3: - resolution: {integrity: sha512-RKshQI1R3YQ+n9YJz2QQ147P66ELpa1FQEg20Dk8oW9t2KgLbpDLLp9aGZ7y8WHSshDknG0bknqGw5/tyCs5tw==} + bidi-js@1.1.0: + resolution: {integrity: sha512-fX1Onk0tdVPC7obPWB5EbJ1z7NVhLq4m2xZLq2YXBkxzMXIGRpNMU88n0EPgWseKl12J7zXs7qrDxPK4sRs2fg==} body-parser@2.3.0: resolution: {integrity: sha512-2cGmJupaNgg+QUwVLAucDuWuoMZ6EX9iHDRswZ5lsNYEmwPaRknMPCLZz07yTzVq/83p4o/wzbDZbBrTvGGTIw==} @@ -2419,8 +2411,8 @@ packages: resolution: {integrity: sha512-ezmVcLR3xAVp8kYOm4GS45ZLLgIE6SPAFoduLr6hTDajwb3KZ2F46gulK3XpcwRFb5KKGCSezCBAY4Dw4HsyXA==} engines: {node: '>=18'} - colord@2.9.3: - resolution: {integrity: sha512-jeC1axXpnb0/2nn/Y1LPuLdgXBLH7aDcHu4KEKfqw3CUhX7ZpfBSlPKyqXE6btIgEzfWtrX3/tyBCaCvXvMkOw==} + colord@2.10.0: + resolution: {integrity: sha512-AidJptpBJmjTclAp9BkLwJi0T93fo5epJnbaZslpg6QVzpHjAiveF55mE9AcUJiGMqRHgMDY8soMsQtuNYMHfw==} combined-stream@1.0.8: resolution: {integrity: sha512-FQN4MRfuJeHf7cBbBMJFXhKSDq+2kAArBlmRBvcvFE5BB1HZKXtSFASDhdlz9zOYwxh8lDdnvmMOe/+5cdoEdg==} @@ -2444,8 +2436,8 @@ packages: resolution: {integrity: sha512-AF3r7P5dWxL8MxyITRMlORQNaOA2IkAFaTr4k7BUumjPtRpGDTZpl0Pb1XCO6JeDCBdp126Cgs9sMxqSjgYyRg==} engines: {node: '>= 0.6'} - compression@1.8.1: - resolution: {integrity: sha512-9mAqGPHLakhCLeNyxPkK4xVo746zQ/czLH1Ky+vkitMnWfWZps8r0qXuwhwizagCRttsL4lfG4pIOvaWLpAP0w==} + compression@1.8.2: + resolution: {integrity: sha512-o8vI5RE5A6EVVOd9o41jKp41aJom+QTEO/Bx8MYNjexMo/Bv2WOjUfZr+aL0WnYSgymUy6zeguqLTsIhV0gMvQ==} engines: {node: '>= 0.8.0'} concurrently@10.0.4: @@ -2724,6 +2716,10 @@ packages: destr@2.0.5: resolution: {integrity: sha512-ugFTXCtDZunbzasqBxrK93Ik/DRYsO6S/fedkWEMKqt04xZ4csmnmwGDBAb07QWNaGMAmnTIemsYZCksjATwsA==} + destroy@1.2.0: + resolution: {integrity: sha512-2sJGJTaXIIaR1w4iJSNoN0hnMY7Gpc/n8D4qSCJw8QqFWXf7cuAgnEHxBpweaVcPevC2l3KpjYCx3NypQQgaJg==} + engines: {node: '>= 0.8', npm: 1.2.8000 || >= 1.4.16} + detect-libc@2.1.2: resolution: {integrity: sha512-Btj2BOOO83o3WyH59e8MgXsxEQVcarkUOpEYrubB0urwnN10yQ364rsiByU11nZlqWYZm05i/of7io4mzihBtQ==} engines: {node: '>=8'} @@ -3735,8 +3731,8 @@ packages: js-tokens@4.0.0: resolution: {integrity: sha512-RdJUflcE3cUzKiMqQgsCu06FPu9UdIJO0beYbPhHN4k6apgJtifcoCtT9bcxOpYBtpD2kCM6Sbzg4CausW/PKQ==} - js-yaml@4.3.1: - resolution: {integrity: sha512-CY6crGq313MX8GkwvB7tzgp99vjQxY1++5y10/BKN/GUfHqWaOGQMNZkBvqSzsZKWk/ijwHlWzzkLulsGHhjWQ==} + js-yaml@4.3.2: + resolution: {integrity: sha512-SFNOvSJ+Dgf/9An904Yx+CgSlIPCkIpao4qo51lpee25TIRejdH3rhR4EZMGoNx3/TP3O+wzWuiTFl4sqbltzA==} hasBin: true jsdom@29.1.1: @@ -4263,8 +4259,8 @@ packages: resolution: {integrity: sha512-YHs7BmmcsdAI5Ozuf8JZo6PT0mv2GIWC9vMfvUC3dp65M8hn7Ux8CPL+2oBI7juNuj9d0ndhTcznq2ODBps9cQ==} engines: {node: '>=18'} - nodemailer@9.0.5: - resolution: {integrity: sha512-wvjiKvjczmsN7U/8006JOdXubgBk2XFAbioDMbT+sM7cPs0QrhJTa6KBRX7P5REGGkDcLUz/EarWidb8G8C1jQ==} + nodemailer@9.1.1: + resolution: {integrity: sha512-izw9mVKFix6YSnC9eLgV6g1opl9DUlRio9ZNcq+Wu9Ujn2UwF+8Nl0B8nz22kEC+CTZCvinkxwJ0DeFbb6NwcQ==} engines: {node: '>=6.0.0'} normalize-path@3.0.0: @@ -5375,20 +5371,20 @@ packages: yaml: optional: true - vitest@4.1.10: - resolution: {integrity: sha512-R9jUTe5S4Qb0HCd4TNqpC7oGcrMssMRGXLW80ubjWsW9VH5GF8y1Y0SFLY9AbqSk6nt0PnOx4H4WNJYZ13GUPw==} + vitest@4.1.11: + resolution: {integrity: sha512-fhACrNXUidIbGSBr5FlbuBkO7VWC1ZyLl0DO4CU2DrQoAPxX84Ysxs+HeGQpii5lZWV1Q4gBZTTu49mF+A6Edw==} engines: {node: ^20.0.0 || ^22.0.0 || >=24.0.0} hasBin: true peerDependencies: '@edge-runtime/vm': '*' '@opentelemetry/api': ^1.9.0 '@types/node': ^20.0.0 || ^22.0.0 || >=24.0.0 - '@vitest/browser-playwright': 4.1.10 - '@vitest/browser-preview': 4.1.10 - '@vitest/browser-webdriverio': 4.1.10 - '@vitest/coverage-istanbul': 4.1.10 - '@vitest/coverage-v8': 4.1.10 - '@vitest/ui': 4.1.10 + '@vitest/browser-playwright': 4.1.11 + '@vitest/browser-preview': 4.1.11 + '@vitest/browser-webdriverio': 4.1.11 + '@vitest/coverage-istanbul': 4.1.11 + '@vitest/coverage-v8': 4.1.11 + '@vitest/ui': 4.1.11 happy-dom: '*' jsdom: '*' vite: ^6.0.0 || ^7.0.0 || ^8.0.0 @@ -5605,7 +5601,7 @@ snapshots: dependencies: '@asamuzakjp/generational-cache': 1.0.1 '@asamuzakjp/nwsapi': 2.3.9 - bidi-js: 1.0.3 + bidi-js: 1.1.0 css-tree: 3.2.1 is-potential-custom-element-name: 1.0.1 @@ -6199,13 +6195,13 @@ snapshots: '@jridgewell/gen-mapping@0.3.12': dependencies: - '@jridgewell/sourcemap-codec': 1.5.0 + '@jridgewell/sourcemap-codec': 1.6.0 '@jridgewell/trace-mapping': 0.3.31 '@jridgewell/gen-mapping@0.3.5': dependencies: '@jridgewell/set-array': 1.2.1 - '@jridgewell/sourcemap-codec': 1.4.10 + '@jridgewell/sourcemap-codec': 1.6.0 '@jridgewell/trace-mapping': 0.3.31 '@jridgewell/remapping@2.3.5': @@ -6217,12 +6213,6 @@ snapshots: '@jridgewell/set-array@1.2.1': {} - '@jridgewell/sourcemap-codec@1.4.10': {} - - '@jridgewell/sourcemap-codec@1.5.0': {} - - '@jridgewell/sourcemap-codec@1.5.5': {} - '@jridgewell/sourcemap-codec@1.6.0': {} '@jridgewell/trace-mapping@0.3.31': @@ -7056,10 +7046,10 @@ snapshots: '@rolldown/pluginutils': 1.0.1 vite: 8.2.1(@types/node@24.13.3)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0) - '@vitest/coverage-v8@4.1.10(vitest@4.1.10)': + '@vitest/coverage-v8@4.1.11(vitest@4.1.11)': dependencies: '@bcoe/v8-coverage': 1.0.2 - '@vitest/utils': 4.1.10 + '@vitest/utils': 4.1.11 ast-v8-to-istanbul: 1.0.3 istanbul-lib-coverage: 3.2.2 istanbul-lib-report: 3.0.1 @@ -7068,65 +7058,65 @@ snapshots: obug: 2.1.2 std-env: 4.1.0 tinyrainbow: 3.1.0 - vitest: 4.1.10(@types/node@26.2.0)(@vitest/coverage-v8@4.1.10)(@vitest/ui@4.1.10)(jsdom@29.1.1)(vite@8.2.1(@types/node@26.2.0)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0)) + vitest: 4.1.11(@types/node@26.2.0)(@vitest/coverage-v8@4.1.11)(@vitest/ui@4.1.11)(jsdom@29.1.1)(vite@8.2.1(@types/node@26.2.0)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0)) - '@vitest/expect@4.1.10': + '@vitest/expect@4.1.11': dependencies: '@standard-schema/spec': 1.1.0 '@types/chai': 5.2.3 - '@vitest/spy': 4.1.10 - '@vitest/utils': 4.1.10 + '@vitest/spy': 4.1.11 + '@vitest/utils': 4.1.11 chai: 6.2.2 tinyrainbow: 3.1.0 - '@vitest/mocker@4.1.10(vite@8.2.1(@types/node@24.13.3)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0))': + '@vitest/mocker@4.1.11(vite@8.2.1(@types/node@24.13.3)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0))': dependencies: - '@vitest/spy': 4.1.10 + '@vitest/spy': 4.1.11 estree-walker: 3.0.3 magic-string: 0.30.21 optionalDependencies: vite: 8.2.1(@types/node@24.13.3)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0) - '@vitest/mocker@4.1.10(vite@8.2.1(@types/node@26.2.0)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0))': + '@vitest/mocker@4.1.11(vite@8.2.1(@types/node@26.2.0)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0))': dependencies: - '@vitest/spy': 4.1.10 + '@vitest/spy': 4.1.11 estree-walker: 3.0.3 magic-string: 0.30.21 optionalDependencies: vite: 8.2.1(@types/node@26.2.0)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0) - '@vitest/pretty-format@4.1.10': + '@vitest/pretty-format@4.1.11': dependencies: tinyrainbow: 3.1.0 - '@vitest/runner@4.1.10': + '@vitest/runner@4.1.11': dependencies: - '@vitest/utils': 4.1.10 + '@vitest/utils': 4.1.11 pathe: 2.0.3 - '@vitest/snapshot@4.1.10': + '@vitest/snapshot@4.1.11': dependencies: - '@vitest/pretty-format': 4.1.10 - '@vitest/utils': 4.1.10 + '@vitest/pretty-format': 4.1.11 + '@vitest/utils': 4.1.11 magic-string: 0.30.21 pathe: 2.0.3 - '@vitest/spy@4.1.10': {} + '@vitest/spy@4.1.11': {} - '@vitest/ui@4.1.10(vitest@4.1.10)': + '@vitest/ui@4.1.11(vitest@4.1.11)': dependencies: - '@vitest/utils': 4.1.10 + '@vitest/utils': 4.1.11 fflate: 0.8.3 flatted: 3.4.2 pathe: 2.0.3 sirv: 3.0.2 tinyglobby: 0.2.17 tinyrainbow: 3.1.0 - vitest: 4.1.10(@types/node@26.2.0)(@vitest/coverage-v8@4.1.10)(@vitest/ui@4.1.10)(jsdom@29.1.1)(vite@8.2.1(@types/node@26.2.0)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0)) + vitest: 4.1.11(@types/node@26.2.0)(@vitest/coverage-v8@4.1.11)(@vitest/ui@4.1.11)(jsdom@29.1.1)(vite@8.2.1(@types/node@26.2.0)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0)) - '@vitest/utils@4.1.10': + '@vitest/utils@4.1.11': dependencies: - '@vitest/pretty-format': 4.1.10 + '@vitest/pretty-format': 4.1.11 convert-source-map: 2.0.0 tinyrainbow: 3.1.0 @@ -7297,7 +7287,7 @@ snapshots: better-result@2.9.2: {} - bidi-js@1.0.3: + bidi-js@1.1.0: dependencies: require-from-string: 2.0.2 @@ -7469,7 +7459,7 @@ snapshots: color-convert: 3.1.3 color-string: 2.1.4 - colord@2.9.3: {} + colord@2.10.0: {} combined-stream@1.0.8: dependencies: @@ -7487,11 +7477,12 @@ snapshots: dependencies: mime-db: 1.54.0 - compression@1.8.1(supports-color@10.2.2): + compression@1.8.2(supports-color@10.2.2): dependencies: bytes: 3.1.2 compressible: 2.0.18 debug: 2.6.9(supports-color@10.2.2) + destroy: 1.2.0 negotiator: 0.6.4 on-headers: 1.1.0 safe-buffer: 5.2.1 @@ -7568,7 +7559,7 @@ snapshots: dependencies: env-paths: 2.2.1 import-fresh: 3.3.0 - js-yaml: 4.3.1 + js-yaml: 4.3.2 parse-json: 5.2.0 optionalDependencies: typescript: 6.0.3 @@ -7577,7 +7568,7 @@ snapshots: dependencies: env-paths: 2.2.1 import-fresh: 3.3.0 - js-yaml: 4.3.1 + js-yaml: 4.3.2 parse-json: 5.2.0 optionalDependencies: typescript: 6.0.3 @@ -7753,6 +7744,8 @@ snapshots: destr@2.0.5: {} + destroy@1.2.0: {} + detect-libc@2.1.2: {} devlop@1.1.0: @@ -8965,7 +8958,7 @@ snapshots: js-tokens@4.0.0: {} - js-yaml@4.3.1: + js-yaml@4.3.2: dependencies: argparse: 2.0.1 @@ -9180,7 +9173,7 @@ snapshots: magic-string@0.30.21: dependencies: - '@jridgewell/sourcemap-codec': 1.5.5 + '@jridgewell/sourcemap-codec': 1.6.0 magicast@0.5.3: dependencies: @@ -9654,7 +9647,7 @@ snapshots: node-releases@2.0.54: {} - nodemailer@9.0.5: {} + nodemailer@9.1.1: {} normalize-path@3.0.0: {} @@ -10569,7 +10562,7 @@ snapshots: '@csstools/media-query-list-parser': 5.0.0(@csstools/css-parser-algorithms@4.0.0(@csstools/css-tokenizer@4.0.0))(@csstools/css-tokenizer@4.0.0) '@csstools/selector-resolve-nested': 4.0.0(postcss-selector-parser@7.1.5) '@csstools/selector-specificity': 6.0.0(postcss-selector-parser@7.1.5) - colord: 2.9.3 + colord: 2.10.0 cosmiconfig: 9.0.2(typescript@6.0.3) css-functions-list: 3.3.3 css-tree: 3.2.1 @@ -10909,15 +10902,15 @@ snapshots: tsx: 4.23.12 yaml: 2.9.0 - vitest@4.1.10(@types/node@24.13.3)(@vitest/coverage-v8@4.1.10)(@vitest/ui@4.1.10)(jsdom@29.1.1)(vite@8.2.1(@types/node@24.13.3)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0)): + vitest@4.1.11(@types/node@24.13.3)(@vitest/coverage-v8@4.1.11)(@vitest/ui@4.1.11)(jsdom@29.1.1)(vite@8.2.1(@types/node@24.13.3)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0)): dependencies: - '@vitest/expect': 4.1.10 - '@vitest/mocker': 4.1.10(vite@8.2.1(@types/node@24.13.3)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0)) - '@vitest/pretty-format': 4.1.10 - '@vitest/runner': 4.1.10 - '@vitest/snapshot': 4.1.10 - '@vitest/spy': 4.1.10 - '@vitest/utils': 4.1.10 + '@vitest/expect': 4.1.11 + '@vitest/mocker': 4.1.11(vite@8.2.1(@types/node@24.13.3)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0)) + '@vitest/pretty-format': 4.1.11 + '@vitest/runner': 4.1.11 + '@vitest/snapshot': 4.1.11 + '@vitest/spy': 4.1.11 + '@vitest/utils': 4.1.11 es-module-lexer: 2.1.0 expect-type: 1.4.0 magic-string: 0.30.21 @@ -10933,21 +10926,21 @@ snapshots: why-is-node-running: 2.3.0 optionalDependencies: '@types/node': 24.13.3 - '@vitest/coverage-v8': 4.1.10(vitest@4.1.10) - '@vitest/ui': 4.1.10(vitest@4.1.10) + '@vitest/coverage-v8': 4.1.11(vitest@4.1.11) + '@vitest/ui': 4.1.11(vitest@4.1.11) jsdom: 29.1.1 transitivePeerDependencies: - msw - vitest@4.1.10(@types/node@26.2.0)(@vitest/coverage-v8@4.1.10)(@vitest/ui@4.1.10)(jsdom@29.1.1)(vite@8.2.1(@types/node@26.2.0)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0)): + vitest@4.1.11(@types/node@26.2.0)(@vitest/coverage-v8@4.1.11)(@vitest/ui@4.1.11)(jsdom@29.1.1)(vite@8.2.1(@types/node@26.2.0)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0)): dependencies: - '@vitest/expect': 4.1.10 - '@vitest/mocker': 4.1.10(vite@8.2.1(@types/node@26.2.0)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0)) - '@vitest/pretty-format': 4.1.10 - '@vitest/runner': 4.1.10 - '@vitest/snapshot': 4.1.10 - '@vitest/spy': 4.1.10 - '@vitest/utils': 4.1.10 + '@vitest/expect': 4.1.11 + '@vitest/mocker': 4.1.11(vite@8.2.1(@types/node@26.2.0)(esbuild@0.28.1)(jiti@2.7.0)(tsx@4.23.12)(yaml@2.9.0)) + '@vitest/pretty-format': 4.1.11 + '@vitest/runner': 4.1.11 + '@vitest/snapshot': 4.1.11 + '@vitest/spy': 4.1.11 + '@vitest/utils': 4.1.11 es-module-lexer: 2.1.0 expect-type: 1.4.0 magic-string: 0.30.21 @@ -10963,8 +10956,8 @@ snapshots: why-is-node-running: 2.3.0 optionalDependencies: '@types/node': 26.2.0 - '@vitest/coverage-v8': 4.1.10(vitest@4.1.10) - '@vitest/ui': 4.1.10(vitest@4.1.10) + '@vitest/coverage-v8': 4.1.11(vitest@4.1.11) + '@vitest/ui': 4.1.11(vitest@4.1.11) jsdom: 29.1.1 transitivePeerDependencies: - msw diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml index 82a3b9e9..535763a9 100644 --- a/pnpm-workspace.yaml +++ b/pnpm-workspace.yaml @@ -13,8 +13,8 @@ catalog: '@types/node': ^24.13.3 '@typescript-eslint/eslint-plugin': ^8.67.0 '@typescript-eslint/parser': ^8.67.0 - '@vitest/coverage-v8': ^4.1.10 - '@vitest/ui': ^4.1.10 + '@vitest/coverage-v8': ^4.1.11 + '@vitest/ui': ^4.1.11 cross-env: ^10.1.0 date-fns: ^4.4.0 eslint: ^10.8.1 @@ -32,7 +32,7 @@ catalog: tsx: ^4.23.12 typescript: ^6.0.3 typescript-eslint: ^8.67.0 - vitest: ^4.1.10 + vitest: ^4.1.11 # Build configuration for pnpm v11 allowBuilds: @@ -57,7 +57,8 @@ overrides: fast-uri: ^3.1.6 # Fixed: GHSA-v2hh-gcrm-f6hx, GHSA-4c8g-83qw-93j6, GHSA-7p8r-x3mc-p8w7, GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf, and GHSA-jqff-g426-hqxp high severity host confusion/SSRF vulnerabilities form-data: ^4.0.6 # Fixed: GHSA-hmw2-7cc7-3qxx CRLF injection vulnerability hono: ^4.12.34 # Fixed: GHSA-xgm2-5f3f-mvvc, GHSA-hvrm-45r6-mjfj, GHSA-w62v-xxxg-mg59, and GHSA-8j4g-w8fx-2239 moderate vulnerabilities - js-yaml: ^4.3.1 # Fixed: GHSA-52cp-r559-cp3m and CVE-2026-59870 high severity quadratic CPU consumption vulnerabilities (!!omap resolution) + js-yaml: ^4.3.2 # Fixed: GHSA-52cp-r559-cp3m, CVE-2026-59870 high (!!omap quadratic CPU), and GHSA-2883-xcg3-v3hh high (maxTotalMergeKeys does not limit CPU use for empty merge sources) + colord: ^2.9.4 # Fixed: GHSA-2wm5-q62r-hmrv moderate slow rejection of oversized malformed color strings nanoid: ^3.3.17 # Fixed: GHSA-2v37-7h3g-55p8 high severity DoS when custom generators run with size zero shell-quote: ^1.8.5 # Fixed: GHSA-395f-4hp3-45gv high severity DoS vulnerability body-parser: ^2.3.0 # Fixed: GHSA-v422-hmwv-36x6 low severity DoS vulnerability