Skip to content

Commit d4950da

Browse files
fix(security): remediate mcp-server and website sub-project deps (#152)
mcp-server (npm): override qs>=6.15.2, fast-uri>=3.1.2 (audit 4->0). website (docusaurus): migrate overrides to pnpm-workspace.yaml + add serialize-javascript, webpack-dev-server, fast-uri, qs, ws, @babel/plugin-transform-modules-systemjs, path-to-regexp (audit 8->1, build verified). Accepted: uuid moderate (major bump, build-time only).
1 parent c0914bf commit d4950da

5 files changed

Lines changed: 755 additions & 618 deletions

File tree

mcp-server/package-lock.json

Lines changed: 10 additions & 6 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

mcp-server/package.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,5 +26,9 @@
2626
"@types/pg": "^8.11.6",
2727
"tsx": "^4.19.2",
2828
"typescript": "^5.7.2"
29+
},
30+
"overrides": {
31+
"qs": ">=6.15.2",
32+
"fast-uri": ">=3.1.2"
2933
}
3034
}

website/package.json

Lines changed: 0 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -43,14 +43,5 @@
4343
},
4444
"engines": {
4545
"node": ">=20.0"
46-
},
47-
"pnpm": {
48-
"overrides": {
49-
"brace-expansion": ">=1.1.13",
50-
"follow-redirects": ">=1.16.0",
51-
"lodash": ">=4.18.1",
52-
"postcss": ">=8.5.10",
53-
"serialize-javascript": ">=7.0.0"
54-
}
5546
}
5647
}

0 commit comments

Comments
 (0)