Skip to content

Commit ad2b814

Browse files
committed
fix(docs): patch vulnerable build deps via overrides; track docs/ in dependabot
Override rollup/picomatch/immutable/postcss/mdast-util-to-hast/preact to patched same-major versions (17 -> 5 advisories). The 5 remaining are dev-server-only esbuild/vite issues needing vite 6 (vitepress 1.6 supports only vite 5); accepted.
1 parent d65d08d commit ad2b814

3 files changed

Lines changed: 190 additions & 374 deletions

File tree

.github/dependabot.yml

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -39,6 +39,19 @@ updates:
3939
npm-dev-deps:
4040
patterns: ["*"]
4141

42+
- package-ecosystem: npm
43+
directory: /docs
44+
schedule:
45+
interval: weekly
46+
groups:
47+
docs-deps:
48+
patterns: ["*"]
49+
# 文档站基于 VitePress 1.6.3(仅支持 vite 5)。vitepress/vite 等大版本升级会破坏
50+
# 文档构建,需协同升级,故不收大版本;安全补丁通过 pnpm-workspace.yaml 的 overrides 处理。
51+
ignore:
52+
- dependency-name: "*"
53+
update-types: ["version-update:semver-major"]
54+
4255
- package-ecosystem: docker
4356
directory: /
4457
schedule:

0 commit comments

Comments
 (0)