mirror of
https://github.com/tiennm99/exchange-rate-export.git
synced 2026-10-11 03:13:21 +00:00
Clears all 23 open advisories (13 high, 10 moderate) on the default branch. next 16.2.10 -> 16.2.11 (18 of the 23 alerts), with eslint-config-next kept in lockstep. Bump the exact-pinned overrides that held two packages at vulnerable versions: js-yaml 4.2.0 -> 4.3.0, postcss 8.5.16 -> 8.5.18. Add two overrides that no upstream bump could reach: - sharp 0.35.0, because next 16.2.11 declares ^0.34.5 and caret on a 0.x version excludes the patched 0.35.0 - brace-expansion 1.1.16 and 5.0.7, scoped per major branch, since minimatch@3 pulls 1.x and minimatch@10 pulls 5.x independently Verified by absence: the lockfile no longer contains next 16.2.10, sharp 0.34.5, postcss 8.5.16, js-yaml 4.2.0, brace-expansion 1.1.14 or 5.0.6. Checking only that patched versions are present would pass while a vulnerable copy survived under a different parent.
34 lines
752 B
JSON
34 lines
752 B
JSON
{
|
|
"name": "exchange-rate-export",
|
|
"version": "0.1.0",
|
|
"packageManager": "pnpm@11.1.1",
|
|
"private": true,
|
|
"scripts": {
|
|
"dev": "next dev --turbopack",
|
|
"build": "next build",
|
|
"start": "next start",
|
|
"lint": "eslint src"
|
|
},
|
|
"dependencies": {
|
|
"@vercel/analytics": "^2.0.1",
|
|
"@vercel/speed-insights": "^2.0.0",
|
|
"axios": "^1.18.1",
|
|
"date-fns": "^4.4.0",
|
|
"next": "16.2.11",
|
|
"react": "^19.2.7",
|
|
"react-datepicker": "^9.1.0",
|
|
"react-dom": "^19.2.7",
|
|
"recharts": "^3.9.2",
|
|
"write-excel-file": "^4.1.1"
|
|
},
|
|
"devDependencies": {
|
|
"@tailwindcss/postcss": "^4",
|
|
"eslint": "^9.39.5",
|
|
"eslint-config-next": "16.2.11",
|
|
"tailwindcss": "^4"
|
|
},
|
|
"engines": {
|
|
"node": ">=24"
|
|
}
|
|
}
|