Skip to content

Commit 5628e58

Browse files
committed
fix(deps): upgrade vulnerable transitive dependencies
Fixes 13 open Dependabot security alerts: - google.golang.org/grpc v1.79.2 → v1.79.3 (critical: auth bypass) - flatted 3.3.3 → 3.4.2 (high: prototype pollution) - picomatch 4.0.3 → 4.0.4, 2.3.1 → 2.3.2 (high+medium: ReDoS, method injection)
1 parent 3ae1a46 commit 5628e58

8 files changed

Lines changed: 869 additions & 870 deletions

File tree

dashboard/package.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@
2222
"@codemirror/lang-python": "^6.2.1",
2323
"@codemirror/lang-sql": "^6.10.0",
2424
"@codemirror/lang-xml": "^6.1.0",
25-
"@codemirror/language": "^6.12.2",
25+
"@codemirror/language": "^6.12.3",
2626
"@codemirror/legacy-modes": "^6.5.2",
2727
"@codemirror/view": "^6.40.0",
2828
"@dnd-kit/core": "^6.3.1",
@@ -47,8 +47,8 @@
4747
"@supabase/ssr": "^0.9.0",
4848
"@supabase/supabase-js": "^2.100.0",
4949
"@tailwindcss/typography": "^0.5.19",
50-
"@uiw/codemirror-theme-okaidia": "^4.25.8",
51-
"@uiw/react-codemirror": "^4.25.8",
50+
"@uiw/codemirror-theme-okaidia": "^4.25.9",
51+
"@uiw/react-codemirror": "^4.25.9",
5252
"class-variance-authority": "^0.7.1",
5353
"clsx": "^2.1.1",
5454
"cmdk": "^1.1.1",

dashboard/pnpm-lock.yaml

Lines changed: 113 additions & 123 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

landingpage/pnpm-lock.yaml

Lines changed: 192 additions & 163 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

src/client/acontext-ts/package-lock.json

Lines changed: 276 additions & 312 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

src/server/api/go/go.mod

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -163,7 +163,7 @@ require (
163163
golang.org/x/tools v0.42.0 // indirect
164164
google.golang.org/genproto/googleapis/api v0.0.0-20260209200024-4cfbd4190f57 // indirect
165165
google.golang.org/genproto/googleapis/rpc v0.0.0-20260209200024-4cfbd4190f57 // indirect
166-
google.golang.org/grpc v1.79.2 // indirect
166+
google.golang.org/grpc v1.79.3 // indirect
167167
google.golang.org/protobuf v1.36.11 // indirect
168168
gorm.io/driver/clickhouse v0.7.0 // indirect
169169
gorm.io/driver/mysql v1.6.0 // indirect

src/server/api/go/go.sum

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -443,8 +443,8 @@ google.golang.org/genproto/googleapis/api v0.0.0-20260209200024-4cfbd4190f57 h1:
443443
google.golang.org/genproto/googleapis/api v0.0.0-20260209200024-4cfbd4190f57/go.mod h1:kSJwQxqmFXeo79zOmbrALdflXQeAYcUbgS7PbpMknCY=
444444
google.golang.org/genproto/googleapis/rpc v0.0.0-20260209200024-4cfbd4190f57 h1:mWPCjDEyshlQYzBpMNHaEof6UX1PmHcaUODUywQ0uac=
445445
google.golang.org/genproto/googleapis/rpc v0.0.0-20260209200024-4cfbd4190f57/go.mod h1:j9x/tPzZkyxcgEFkiKEEGxfvyumM01BEtsW8xzOahRQ=
446-
google.golang.org/grpc v1.79.2 h1:fRMD94s2tITpyJGtBBn7MkMseNpOZU8ZxgC3MMBaXRU=
447-
google.golang.org/grpc v1.79.2/go.mod h1:KmT0Kjez+0dde/v2j9vzwoAScgEPx/Bw1CYChhHLrHQ=
446+
google.golang.org/grpc v1.79.3 h1:sybAEdRIEtvcD68Gx7dmnwjZKlyfuc61Dyo9pGXXkKE=
447+
google.golang.org/grpc v1.79.3/go.mod h1:KmT0Kjez+0dde/v2j9vzwoAScgEPx/Bw1CYChhHLrHQ=
448448
google.golang.org/protobuf v1.26.0-rc.1/go.mod h1:jlhhOSvTdKEhbULTjvd4ARK9grFBp09yW+WbY/TyQbw=
449449
google.golang.org/protobuf v1.27.1/go.mod h1:9q0QmTI4eRPtz6boOQmLYwt+qCgq0jsYwAQnmE0givc=
450450
google.golang.org/protobuf v1.36.11 h1:fV6ZwhNocDyBLK0dj+fg8ektcVegBBuEolpbTQyBNVE=

src/server/ui/package.json

Lines changed: 14 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
"@codemirror/lang-python": "^6.2.1",
2020
"@codemirror/lang-sql": "^6.10.0",
2121
"@codemirror/lang-xml": "^6.1.0",
22-
"@codemirror/language": "^6.12.2",
22+
"@codemirror/language": "^6.12.3",
2323
"@codemirror/legacy-modes": "^6.5.2",
2424
"@codemirror/view": "^6.40.0",
2525
"@dnd-kit/core": "^6.3.1",
@@ -29,22 +29,22 @@
2929
"@radix-ui/react-alert-dialog": "^1.1.15",
3030
"@radix-ui/react-dialog": "^1.1.15",
3131
"@radix-ui/react-dropdown-menu": "^2.1.16",
32-
"@radix-ui/react-label": "^2.1.7",
33-
"@radix-ui/react-select": "^2.1.15",
32+
"@radix-ui/react-label": "^2.1.8",
33+
"@radix-ui/react-select": "^2.2.6",
3434
"@radix-ui/react-separator": "^1.1.8",
35-
"@radix-ui/react-slot": "^1.2.3",
35+
"@radix-ui/react-slot": "^1.2.4",
3636
"@radix-ui/react-switch": "^1.2.6",
3737
"@radix-ui/react-tabs": "^1.1.13",
3838
"@radix-ui/react-tooltip": "^1.2.8",
39-
"@uiw/codemirror-theme-okaidia": "^4.25.8",
40-
"@uiw/react-codemirror": "^4.25.8",
39+
"@uiw/codemirror-theme-okaidia": "^4.25.9",
40+
"@uiw/react-codemirror": "^4.25.9",
4141
"class-variance-authority": "^0.7.1",
4242
"clsx": "^2.1.1",
4343
"lucide-react": "^0.577.0",
4444
"next": "15.5.14",
4545
"next-intl": "^4.8.3",
4646
"next-themes": "^0.4.6",
47-
"ofetch": "^1.4.1",
47+
"ofetch": "^1.5.1",
4848
"pg": "^8.20.0",
4949
"radix-ui": "^1.4.3",
5050
"react": "19.2.4",
@@ -59,16 +59,16 @@
5959
},
6060
"devDependencies": {
6161
"@eslint/eslintrc": "^3.3.5",
62-
"@tailwindcss/postcss": "^4",
63-
"@types/node": "^25",
62+
"@tailwindcss/postcss": "^4.2.2",
63+
"@types/node": "^25.5.0",
6464
"@types/pg": "^8.20.0",
65-
"@types/react": "^19",
66-
"@types/react-dom": "^19",
67-
"eslint": "^9",
65+
"@types/react": "^19.2.14",
66+
"@types/react-dom": "^19.2.3",
67+
"eslint": "^9.39.4",
6868
"eslint-config-next": "16.2.1",
69-
"tailwindcss": "^4",
69+
"tailwindcss": "^4.2.2",
7070
"tw-animate-css": "^1.4.0",
71-
"typescript": "^5"
71+
"typescript": "^5.9.3"
7272
},
7373
"pnpm": {
7474
"overrides": {

0 commit comments

Comments
 (0)