Skip to content
This repository was archived by the owner on Dec 13, 2025. It is now read-only.

Commit 3aadbb6

Browse files
committed
πŸ”’ Fix security vulnerabilities in dependencies
- next: 15.2.4 β†’ 15.2.6+ (critical RCE fix) - mermaid: 11.7.0 β†’ 11.10.0+ (XSS fixes) - eslint: 9.23.0 β†’ 9.39.1 (plugin-kit ReDoS fix) - @marp-team/marp-core: 4.0.1 β†’ 4.2.0 (js-yaml fix) - Add pnpm overrides for transitive dependencies
1 parent 8623b40 commit 3aadbb6

File tree

2 files changed

+513
-561
lines changed

2 files changed

+513
-561
lines changed

β€Žpackage.jsonβ€Ž

Lines changed: 13 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@
1414
"start": "next start"
1515
},
1616
"dependencies": {
17-
"@marp-team/marp-core": "^4.0.1",
17+
"@marp-team/marp-core": "^4.2.0",
1818
"@naverpay/commithelper-go": "^1.0.1",
1919
"@naverpay/eslint-config": "^2.2.4",
2020
"@naverpay/eslint-plugin": "^2.1.1",
@@ -27,12 +27,12 @@
2727
"@vercel/analytics": "^1.5.0",
2828
"classnames": "^2.5.1",
2929
"date-fns": "^4.1.0",
30-
"eslint": "^9.23.0",
30+
"eslint": "^9.39.1",
3131
"gray-matter": "^4.0.3",
3232
"lefthook": "^1.11.5",
3333
"markdown-it-mermaid": "^0.2.5",
34-
"mermaid": "^11.7.0",
35-
"next": "^15.2.4",
34+
"mermaid": "^11.10.0",
35+
"next": "^15.2.6",
3636
"next-themes": "^0.4.6",
3737
"postcss": "^8.5.3",
3838
"postcss-import-url": "^7.2.0",
@@ -52,6 +52,14 @@
5252
"pnpm": {
5353
"onlyBuiltDependencies": [
5454
"lefthook"
55-
]
55+
],
56+
"overrides": {
57+
"markdown-it-mermaid>mermaid": "^11.10.0",
58+
"js-yaml": "^4.1.1",
59+
"brace-expansion@>=1.0.0 <1.1.12": "^1.1.12",
60+
"brace-expansion@>=2.0.0 <2.0.2": "^2.0.2",
61+
"@eslint/plugin-kit": "^0.3.4",
62+
"lodash.trim": "npm:lodash@^4.17.21"
63+
}
5664
}
5765
}

0 commit comments

Comments
Β (0)