-
Notifications
You must be signed in to change notification settings - Fork 33
Expand file tree
/
Copy pathpnpm-workspace.yaml
More file actions
203 lines (197 loc) · 7.87 KB
/
Copy pathpnpm-workspace.yaml
File metadata and controls
203 lines (197 loc) · 7.87 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
packages:
- .claude/hooks/*
- '.config/oxlint-plugin'
- '.config/oxlint-plugin/fleet/*'
allowBuilds:
cpu-features: false
esbuild: true
protobufjs: false
ssh2: false
autoInstallPeers: true
blockExoticSubdeps: true
catalog:
'@redwoodjs/agent-ci': 0.16.2
'@sinclair/typebox': 0.34.49
'@socketregistry/packageurl-js': 1.4.2
'@socketregistry/packageurl-js-stable': npm:@socketregistry/packageurl-js@1.4.2
'@socketsecurity/lib': 6.0.8
'@socketsecurity/lib-stable': npm:@socketsecurity/lib@6.0.8
'@socketsecurity/registry': 2.0.2
'@socketsecurity/registry-stable': npm:@socketsecurity/registry@2.0.2
'@socketsecurity/sdk': 4.0.1
'@socketsecurity/sdk-stable': npm:@socketsecurity/sdk@4.0.1
'@types/mdast': 4.0.4
'@types/node': 24.9.2
'@types/shell-quote': 1.7.5
'@typescript/native-preview': 7.0.0-dev.20260510.1
'@vitest/coverage-v8': 4.1.8
'@vitest/ui': 4.1.8
'dtu-github-actions': 0.16.2
'ecc-agentshield': 1.4.0
'mdast-util-from-markdown': 2.0.3
'micromark': 4.0.2
'npm-run-all2': 9.0.1
'oxfmt': 0.48.0
'oxlint': 1.63.0
'playwright-core': 1.60.0
'regjsparser': 0.13.1
'rolldown': 1.1.0
'shell-quote': 1.8.4
'taze': 19.14.1
'untracked': 1.6.1
'vitest': 4.1.8
enablePrePostScripts: true
# Force every consumer of Socket's own packages to resolve through the
# catalog-pinned published versions. The `catalog:` form rewrites
# `workspace:*`, `^x.y.z`, and bare-version specs alike to the version
# in the default `catalog:` block above. This defeats accidental
# local-checkout resolution when a sibling repo is on disk.
overrides:
# Fleet-canonical overrides (managed by socket-wheelhouse sync; do not edit).
'@socketregistry/packageurl-js': 'catalog:'
'@socketsecurity/lib': 'catalog:'
'@socketsecurity/registry': 'catalog:'
'@socketsecurity/sdk': 'catalog:'
'chalk@>=5': '5.6.2'
'es-define-property': 'npm:@socketregistry/es-define-property@1.0.7'
'es-set-tostringtag': 'npm:@socketregistry/es-set-tostringtag@1.0.10'
'function-bind': 'npm:@socketregistry/function-bind@1.0.7'
'glob': '13.0.6'
'gopd': 'npm:@socketregistry/gopd@1.0.7'
'has-symbols': 'npm:@socketregistry/has-symbols@1.0.7'
'has-tostringtag': 'npm:@socketregistry/has-tostringtag@1.0.7'
'hasown': 'npm:@socketregistry/hasown@1.0.7'
'iconv-lite': '0.7.2'
'isexe@>=3': '4.0.0'
'lru-cache@>=10': '11.3.6'
'magic-string': '0.30.21'
'mime-db': '1.54.0'
'mime-types@>=3': '3.0.2'
'minipass@>=4': '7.1.3'
'safe-buffer': 'npm:@socketregistry/safe-buffer@1.0.9'
'safer-buffer': 'npm:@socketregistry/safer-buffer@1.0.10'
'semver@>=5.0.0 <7.6.0': '7.8.1'
'side-channel': 'npm:@socketregistry/side-channel@1.0.10'
'ssri@>=12': '13.0.1'
'string-width@>=5': '8.1.0'
'update-notifier@>=4.0.0': '7.3.1'
'uuid': '11.1.1'
'which@>=4': '7.0.0'
'wrap-ansi@>=8': '9.0.2'
'yaml@2': '2.9.0'
# Repo-specific overrides below.
'@hono/node-server': '1.19.13'
'fast-uri': '3.1.2'
# GHSA-xrhx-7g5j-rcj5 IPv6 deny-rule bypass / GHSA-3hrh-pfw6-9m5x Set-Cookie
# injection / GHSA-f577-qrjj-4474 JWT scheme / GHSA-2gcr-mfcq-wcc3 mount
# prefix; transitive via @modelcontextprotocol/sdk, fixed in 4.12.21
'hono': '4.12.23'
'ip-address': '10.1.1'
# CVE-2026-... node-forge prototype-pollution-class advisories #55/#57/#59/#61
'node-forge': '1.4.0'
# GHSA-9wv6-86v2-598j path-to-regexp DoS / GHSA-rhx6-c78j-4q9w; advisories #51/#53
'path-to-regexp': '8.4.2'
# GHSA-q8mj-m7cp-5q26 qs (transitive via express/body-parser); fixed in 6.15.2
'qs': '6.15.2'
# GHSA-w7jw-789q-3m8p quote() does not escape newlines in object .op values
# (transitive via npm-run-all2); fixed in 1.8.4
'shell-quote': '1.8.4'
# advisory #42 GHSA-ph9p-34f9-6g65 symlink-traversal;
# advisory #104 GHSA-7c78-jf6q-g5cm type-confusion path traversal; fixed in 0.2.7
'tmp': '0.2.7'
# GHSA-fx2h-pf6j-xcff server.fs.deny bypass / GHSA-v6wh-96g9-6wx3 NTLMv2
# hash disclosure (Windows); transitive via vitest, fixed in 8.0.16
'vite': '8.0.16'
'zod': '3.25.76'
'zod-to-json-schema': '3.25.1'
minimumReleaseAge: 10080
minimumReleaseAgeExclude:
- '@socketaddon/*'
- '@socketbin/*'
- '@socketregistry/*'
- '@socketsecurity/*'
- '@stuie/*'
- '@socketdev/*'
- 'sfw'
- '@ultrathink/*'
# security fix for GHSA-ph9p-34f9-6g65; bypassing soak to land the patch now
- '@socketoverride/*'
# published: 2026-06-09 | removable: 2026-06-16
- '@yuku-parser/binding-darwin-arm64@0.5.31'
# published: 2026-06-09 | removable: 2026-06-16
- '@yuku-parser/binding-darwin-x64@0.5.31'
# published: 2026-06-09 | removable: 2026-06-16
- '@yuku-parser/binding-freebsd-x64@0.5.31'
# published: 2026-06-09 | removable: 2026-06-16
- '@yuku-parser/binding-linux-arm-gnu@0.5.31'
# published: 2026-06-09 | removable: 2026-06-16
- '@yuku-parser/binding-linux-arm-musl@0.5.31'
# published: 2026-06-09 | removable: 2026-06-16
- '@yuku-parser/binding-linux-arm64-gnu@0.5.31'
# published: 2026-06-09 | removable: 2026-06-16
- '@yuku-parser/binding-linux-arm64-musl@0.5.31'
# published: 2026-06-09 | removable: 2026-06-16
- '@yuku-parser/binding-linux-x64-gnu@0.5.31'
# published: 2026-06-09 | removable: 2026-06-16
- '@yuku-parser/binding-linux-x64-musl@0.5.31'
# published: 2026-06-09 | removable: 2026-06-16
- '@yuku-parser/binding-win32-arm64@0.5.31'
# published: 2026-06-09 | removable: 2026-06-16
- '@yuku-parser/binding-win32-x64@0.5.31'
- 'socket'
# published: 2026-06-08 | removable: 2026-06-15
- 'oxfmt@0.54.0'
# published: 2026-06-08 | removable: 2026-06-15
- '@oxfmt/binding-android-arm-eabi@0.54.0'
# published: 2026-06-08 | removable: 2026-06-15
- '@oxfmt/binding-android-arm64@0.54.0'
# published: 2026-06-08 | removable: 2026-06-15
- '@oxfmt/binding-darwin-arm64@0.54.0'
# published: 2026-06-08 | removable: 2026-06-15
- '@oxfmt/binding-darwin-x64@0.54.0'
# published: 2026-06-08 | removable: 2026-06-15
- '@oxfmt/binding-freebsd-x64@0.54.0'
# published: 2026-06-08 | removable: 2026-06-15
- '@oxfmt/binding-linux-arm-gnueabihf@0.54.0'
# published: 2026-06-08 | removable: 2026-06-15
- '@oxfmt/binding-linux-arm-musleabihf@0.54.0'
# published: 2026-06-08 | removable: 2026-06-15
- '@oxfmt/binding-linux-arm64-gnu@0.54.0'
# published: 2026-06-08 | removable: 2026-06-15
- '@oxfmt/binding-linux-arm64-musl@0.54.0'
# published: 2026-06-08 | removable: 2026-06-15
- '@oxfmt/binding-linux-ppc64-gnu@0.54.0'
# published: 2026-06-08 | removable: 2026-06-15
- '@oxfmt/binding-linux-riscv64-gnu@0.54.0'
# published: 2026-06-08 | removable: 2026-06-15
- '@oxfmt/binding-linux-riscv64-musl@0.54.0'
# published: 2026-06-08 | removable: 2026-06-15
- '@oxfmt/binding-linux-s390x-gnu@0.54.0'
# published: 2026-06-08 | removable: 2026-06-15
- '@oxfmt/binding-linux-x64-gnu@0.54.0'
# published: 2026-06-08 | removable: 2026-06-15
- '@oxfmt/binding-linux-x64-musl@0.54.0'
# published: 2026-06-08 | removable: 2026-06-15
- '@oxfmt/binding-openharmony-arm64@0.54.0'
# published: 2026-06-08 | removable: 2026-06-15
- '@oxfmt/binding-win32-arm64-msvc@0.54.0'
# published: 2026-06-08 | removable: 2026-06-15
- '@oxfmt/binding-win32-ia32-msvc@0.54.0'
# published: 2026-06-08 | removable: 2026-06-15
- '@oxfmt/binding-win32-x64-msvc@0.54.0'
# Transitional: warn (not error) while the socket-registry CI install chain
# still ships pnpm 11.5.1 and this repo runs 11.6.0. Restore to error once the
# registry reusable-workflow nested pin delivers 11.6.0.
pmOnFail: warn
resolutionMode: highest
saveExact: true
trustPolicy: no-downgrade
trustPolicyExclude:
# Transitive dep of @vitest/coverage-v8 (catalog-pinned 4.1.6).
# Authored by ariperkkio, the vitest coverage maintainer
# (github.com/AriPerkkio/ast-v8-to-istanbul); Socket's no-downgrade
# gate flags 1.0.2 only because it published 2026-05-25 (inside the
# soak window). Legitimate first-party vitest tooling, not a takeover.
- 'ast-v8-to-istanbul@1.0.2'
- 'compromise@14.15.0'
- 'undici-types@6.21.0'