pnpm 10.32 stopped reading the "pnpm" field from package.json, so the undici/picomatch overrides and the three GHSA suppressions had silently stopped applying — only the stale lockfile still held undici at 7.24.8. Move the surviving picomatch override to pnpm-workspace.yaml. With the config live again, two high advisories surfaced: - postcss was stuck at 8.5.15 (GHSA-r28c-9q8g-f849, patched in 8.5.18); nothing pinned it, so refresh to 8.5.25 within vite's range. - undici GHSA-4cwx-7wf7-3272 needed >=7.29.0, but our ~7.24.0 pin existed because jsdom 29 crashed on undici 7.28+. jsdom 30 moved to undici ^8.9, so bump jsdom and drop both the pin and all three suppressions. 15 vulnerabilities (5 high, 3 suppressed) down to 1 moderate (smol-toml via knip, below the --audit-level=high gate). Separately, ports.ts declared its members with method shorthand, which TypeScript treats as this-dependent, so oxlint's unbound-method fired wherever a port was passed by reference (use-bestiary.ts:236). The ports are bags of plain module functions, so declare them as readonly function properties instead of suppressing the one call site. This makes parameter types contravariant rather than bivariant; typecheck passes unchanged. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
35 lines
1.4 KiB
JSON
35 lines
1.4 KiB
JSON
{
|
|
"private": true,
|
|
"packageManager": "pnpm@10.32.1+sha512.a706938f0e89ac1456b6563eab4edf1d1faf3368d1191fc5c59790e96dc918e4456ab2e67d613de1043d2e8c81f87303e6b40d4ffeca9df15ef1ad567348f2be",
|
|
"devDependencies": {
|
|
"@biomejs/biome": "2.4.8",
|
|
"@vitest/coverage-v8": "^4.1.0",
|
|
"jscpd": "^4.0.8",
|
|
"jsinspect-plus": "^3.1.3",
|
|
"knip": "^5.88.1",
|
|
"lefthook": "^2.1.4",
|
|
"oxlint": "^1.56.0",
|
|
"oxlint-tsgolint": "^0.17.1",
|
|
"typescript": "^5.8.0",
|
|
"vitest": "^4.1.0"
|
|
},
|
|
"scripts": {
|
|
"prepare": "lefthook install",
|
|
"format": "biome format --write .",
|
|
"format:check": "biome format .",
|
|
"lint": "biome lint .",
|
|
"lint:fix": "biome lint --write .",
|
|
"typecheck": "tsc --build",
|
|
"test": "vitest run",
|
|
"test:watch": "vitest",
|
|
"knip": "knip",
|
|
"jscpd": "jscpd",
|
|
"jsinspect": "jsinspect -c .jsinspectrc apps/web/src packages/domain/src packages/application/src",
|
|
"oxlint": "oxlint --tsconfig tsconfig.json --type-aware --deny-warnings",
|
|
"check:ignores": "node scripts/check-lint-ignores.mjs",
|
|
"check:classnames": "node scripts/check-cn-classnames.mjs",
|
|
"check:props": "node scripts/check-component-props.mjs",
|
|
"check": "pnpm audit --audit-level=high && knip && biome check . && node scripts/check-lint-ignores.mjs && node scripts/check-cn-classnames.mjs && node scripts/check-component-props.mjs && jscpd && pnpm jsinspect && tsc --build && oxlint --tsconfig tsconfig.json --type-aware --deny warnings && vitest run"
|
|
}
|
|
}
|