Bump @nuxt/ui to 4.11.1 to clear the Tiptap advisories - #4
Merged
Merged
Conversation
@tiptap/core 3.30.3 carries two advisories — a quadratic ReDoS in Markdown attribute parsing (high, fixed in 3.30.5) and mergeAttributes() turning an own __proto__ key into inherited executable DOM attributes (moderate, fixed in 3.30.4). Nothing here depends on Tiptap directly; the whole family arrives through @nuxt/ui. `npm audit fix` is not the fix. It upgrades @tiptap/starter-kit and nests a private @tiptap/core 3.31.3 underneath it, while the hoisted copy @nuxt/ui actually resolves stays on 3.30.3 — two copies in the bundle, the vulnerable one still reachable. @nuxt/ui 4.11.0 asks for ^3.29.2 across seventeen @tiptap packages, and the extensions peer-depend on an exact core version, so the family only moves as a unit. 4.11.1 asks for ^3.31.3 throughout, which lifts all of them together and leaves a single @tiptap/core 3.31.3 in the tree. Verified: nuxt build, eslint and nuxt typecheck all pass, and the dashboard renders and reads settings unchanged against the running API, with no console errors. Two advisories remain in this lockfile and are untouched here: js-yaml 4.3.1 (high) and esbuild 0.27.7 (low). Both are present on main at the same versions and are unrelated to Tiptap. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The advisories
@tiptap/core3.30.3 carries two:3.30.5mergeAttributes()turns an own__proto__key into inherited executable DOM attributes3.30.4Nothing in
clients/dashboarddepends on Tiptap directly — the whole family arrives through@nuxt/ui.Why not
npm audit fixI tried it first. It is not the fix: it upgrades
@tiptap/starter-kitand nests a private@tiptap/core3.31.3 beneath it, while the hoisted copy@nuxt/uiactually resolves stays on 3.30.3.Two copies in the bundle and the vulnerable one still in the graph. Reverted.
What this does instead
@nuxt/ui4.11.0 asks for^3.29.2across seventeen@tiptap/*packages, and the extensions peer-depend on an exact core version — so the family only moves as a unit. 4.11.1 asks for^3.31.3throughout, which lifts all of them together:Both advisories clear.
Verified
nuxt build— succeeds, 1.84 MB total (454 kB gzip)eslint .— cleannuxt typecheck— cleanNot addressed here
Two unrelated advisories remain in this lockfile:
js-yaml4.3.1 (high —maxTotalMergeKeysdoes not limit CPU on empty merge sources) andesbuild0.27.7 (low — arbitrary file read via the dev server on Windows). Both are present onmainat identical versions and neither was introduced by this change. Worth a follow-up; kept out to keep this diff to the Tiptap fix.🤖 Generated with Claude Code