Replace pnpm-lock.yaml with package-lock.json. The seven security overrides
move to package.json#overrides, including the two version-scoped
brace-expansion entries, which npm resolves per major branch the same way
pnpm did.
pnpm-workspace.yaml's allowBuilds becomes package.json#allowScripts: npm 11
gates dependency install scripts the same way, so sharp and unrs-resolver stay
explicitly approved rather than silently enabled.
Updated dependencies to fix Next.js and React CVE vulnerabilities.
The fix-react2shell-next tool automatically updated the following packages to their secure versions:
- next
- react-server-dom-webpack
- react-server-dom-parcel
- react-server-dom-turbopack
All package.json files have been scanned and vulnerable versions have been patched to the correct fixed versions based on the official React advisory.
Co-authored-by: Vercel <vercel[bot]@users.noreply.github.com>