diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index ae5159bb5a..02e6642fe5 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -35,6 +35,9 @@ overrides: hono@<5.0.0: ^4.12.34 dompurify@<4.0.0: ^3.4.13 nanoid@<4.0.0: ^3.3.17 + '@xmldom/xmldom@>=0.8.0 <0.9.0': ^0.8.15 + '@xmldom/xmldom@>=0.9.0 <0.10.0': ^0.9.12 + qs@>=6.0.0 <7.0.0: ^6.16.0 importers: @@ -5356,15 +5359,13 @@ packages: resolution: {integrity: sha512-CJDxIgE5I0FH+ttq/Fxy6nRpxP70+e2O048EPe85J2use3XKdatVM7dDVvFNjQudd9B49NPoZ+8PG49zj4Er8Q==} engines: {node: '>= 16'} - '@xmldom/xmldom@0.8.13': - resolution: {integrity: sha512-KRYzxepc14G/CEpEGc3Yn+JKaAeT63smlDr+vjB8jRfgTBBI9wRj/nkQEO+ucV8p8I9bfKLWp37uHgFrbntPvw==} + '@xmldom/xmldom@0.8.15': + resolution: {integrity: sha512-/5NV/vDALVFDXgLmfsy9TRCBlKwO2LNBFzpzvb9iIj+jR+eSc6DLYYvVOdivT/jm7MtU6TebYuRmzEOI7w40UA==} engines: {node: '>=10.0.0'} - deprecated: this version has critical issues, please update to the latest version - '@xmldom/xmldom@0.9.11': - resolution: {integrity: sha512-tW8bcK3hsG0/uqSnNz6TK4BkcuZSezoU7DlnYssILmZDktPnSHHuDJJFM0AJv+13gz2r0iGdrj6qqKeUnxXEDg==} + '@xmldom/xmldom@0.9.12': + resolution: {integrity: sha512-5AXjrcMClTryPe9LgZrygpB1lj7s0S9E0+W+AHaVKAVyHanafK86iPSvG5xHVSp/jC+VH1UXu0TAEmY279xH7A==} engines: {node: '>=14.6'} - deprecated: this version has critical issues, please update to the latest version '@yuku-analyzer/binding-android-arm64@0.8.7': resolution: {integrity: sha512-pzJ++UMCZEV4s6SP3Ryvj+snWP8s7aTXFkSXRyeBF4RSALftPzfqYssHdGOmOH2QnRAtyOhhg64tdjeSGJvYRg==} @@ -8249,8 +8250,8 @@ packages: pure-rand@8.4.2: resolution: {integrity: sha512-vvuOGgcuPJAirlHvuQw1TrOiw7ptaIXXmIbNuiNOY6lNGJJH49PQ1Kj4nd783nPdQhQdicgOjVI2yI/9BD6/Ng==} - qs@6.15.3: - resolution: {integrity: sha512-O9gl3zCl5h5blw1KGUzQKhA5oUXSl8rwUIM5o0S3nCXMliSvy5Dzx7/DJcI+SwgICv+IneSZwhBh1oSyEHA71A==} + qs@6.16.0: + resolution: {integrity: sha512-h6fhOIaRrID2CbEY2fqs+7t+UXZo+MLAnU5gRIq85uFtdiUPCdsApMlHhXogKVM4HM2DVbIjGNTTYH2OcmP1vA==} engines: {node: '>=0.6'} quickjs-emscripten-core@0.32.0: @@ -9297,7 +9298,7 @@ snapshots: '@authenio/xml-encryption@2.0.2': dependencies: - '@xmldom/xmldom': 0.8.13 + '@xmldom/xmldom': 0.8.15 escape-html: 1.0.3 xpath: 0.0.32 @@ -9701,7 +9702,7 @@ snapshots: '@better-auth/core': 1.7.2(@better-auth/utils@0.4.2)(@better-fetch/fetch@1.3.1)(@cloudflare/workers-types@4.20260520.1)(@opentelemetry/api@1.9.1)(better-call@1.4.0(zod@4.4.3))(jose@6.2.8)(kysely@0.29.4)(nanostores@1.4.0) '@better-auth/utils': 0.4.2 '@better-fetch/fetch': 1.3.1 - '@xmldom/xmldom': 0.9.11 + '@xmldom/xmldom': 0.9.12 better-auth: 1.7.2(@cloudflare/workers-types@4.20260520.1)(@opentelemetry/api@1.9.1)(better-sqlite3@12.11.1)(mongodb@7.5.0(socks@2.8.9))(mysql2@3.23.3(@types/node@26.2.0))(next@16.3.1(@opentelemetry/api@1.9.1)(@playwright/test@1.62.1)(@types/node@26.2.0)(react-dom@19.2.8(react@19.2.8))(react@19.2.8))(pg@8.22.0)(react-dom@19.2.8(react@19.2.8))(react@19.2.8)(svelte@5.56.9(@typescript-eslint/types@8.67.0))(vitest@4.1.10) better-call: 1.4.0(zod@4.4.3) fast-xml-parser: 5.10.1 @@ -11679,9 +11680,9 @@ snapshots: '@xmldom/is-dom-node@1.0.1': {} - '@xmldom/xmldom@0.8.13': {} + '@xmldom/xmldom@0.8.15': {} - '@xmldom/xmldom@0.9.11': {} + '@xmldom/xmldom@0.9.12': {} '@yuku-analyzer/binding-android-arm64@0.8.7': optional: true @@ -11983,7 +11984,7 @@ snapshots: http-errors: 2.0.1 iconv-lite: 0.7.3 on-finished: 2.4.1 - qs: 6.15.3 + qs: 6.16.0 raw-body: 3.0.2 type-is: 2.1.0 transitivePeerDependencies: @@ -12781,7 +12782,7 @@ snapshots: once: 1.4.0 parseurl: 1.3.3 proxy-addr: 2.0.7 - qs: 6.15.3 + qs: 6.16.0 range-parser: 1.3.0 router: 2.2.0 send: 1.2.1 @@ -14781,7 +14782,7 @@ snapshots: pure-rand@8.4.2: {} - qs@6.15.3: + qs@6.16.0: dependencies: es-define-property: 1.0.1 side-channel: 1.1.1 @@ -15101,7 +15102,7 @@ snapshots: samlify@2.13.1: dependencies: '@authenio/xml-encryption': 2.0.2 - '@xmldom/xmldom': 0.8.13 + '@xmldom/xmldom': 0.8.15 node-rsa: 1.1.1 xml: 1.0.1 xml-crypto: 6.1.2 @@ -15885,7 +15886,7 @@ snapshots: xml-crypto@6.1.2: dependencies: '@xmldom/is-dom-node': 1.0.1 - '@xmldom/xmldom': 0.8.13 + '@xmldom/xmldom': 0.8.15 xpath: 0.0.33 xml-escape@1.1.0: {} diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml index 857abe7881..64f295ebb0 100644 --- a/pnpm-workspace.yaml +++ b/pnpm-workspace.yaml @@ -295,3 +295,36 @@ overrides: # `<3.3.17`, which would self-invalidate the day 3.3.17 is itself flagged # (the undici 7.28.0 / brace-expansion 5.0.8 specimens, #4961 / #5032). 'nanoid@<4.0.0': '^3.3.17' + # OSV 2026-09-02 (#14639) — four advisories, every one naming a fixed + # version, so this is the "take the fix" path osv-scanner.toml's own header + # describes and NOT an exemption; that ledger holds zero entries and the + # triage ruling is that it stays at zero. + # @xmldom/xmldom GHSA-6gmq-8vp8-gcm6 (6.3 medium) — flagged on BOTH + # resolved lines: 0.8.13 (fixed 0.8.15) and 0.9.11 (fixed 0.9.12). That + # is why this needs TWO selectors and not one. A single lower-bounded + # selector at the fixed 0.9.12 would drag the 0.8 consumers across a 0.x + # MINOR — the compatibility boundary for a 0.x package — past every + # range they declare. Measured dependents and their declared ranges: + # 0.8.13 <- @authenio/xml-encryption@2.0.2 (^0.8.6), + # samlify@2.13.1 (^0.8.11), xml-crypto@6.1.2 (^0.8.10) + # 0.9.11 <- @better-auth/sso@1.7.2 (^0.9.10) + # Each of those ranges already admits its own fixed version, so both + # entries are a dedupe onto the patched line rather than a forced + # upgrade past what a dependent supports — the dompurify / nanoid shape + # above, and the reason no dependent manifest has to move in lockstep. + # qs GHSA-4mjr-xmp4-gh2g and GHSA-x5fp-wj9c-mxmx (6.3 medium each) — one + # resolved line, 6.15.3, fixed 6.16.0. Dependents body-parser@2.3.0 + # (^6.15.2) and express@5.2.1 (^6.14.0) both admit it. + # Transitive-only, like dompurify and nanoid above: no workspace manifest + # declares either package, so there is no publishable declared range to + # keep in lockstep and check-override-consistency.mjs lists both as + # overrides it cannot cross-check against a declared range. That is + # correct for this shape, and it is a report, never a failure. + # Bounds sit at the compatibility boundary — 0.9.0 and 0.10.0 for the two + # 0.x lines, 7.0.0 for qs — per this block's header rule, never at the + # fixed version itself, which would self-invalidate the day that version + # is the one flagged (the undici 7.28.0 / brace-expansion 5.0.8 + # specimens, #4961 / #5032). + '@xmldom/xmldom@>=0.8.0 <0.9.0': '^0.8.15' + '@xmldom/xmldom@>=0.9.0 <0.10.0': '^0.9.12' + 'qs@>=6.0.0 <7.0.0': '^6.16.0'