fix: resolve npm audit vulnerabilities (#16264)

This commit is contained in:
Hiep Le
2026-08-04 20:09:25 +07:00
committed by GitHub
parent 0ffcb659d1
commit 1a88ae6377
3 changed files with 692 additions and 1029 deletions
+660 -1012
View File
File diff suppressed because it is too large Load Diff
+11 -8
View File
@@ -25,8 +25,8 @@
"@monaco-editor/react": "4.7.0",
"@openhands/extensions": "0.13.0",
"@openhands/typescript-client": "1.36.1",
"@react-router/node": "7.17.0",
"@react-router/serve": "7.17.0",
"@react-router/node": "7.18.2",
"@react-router/serve": "7.18.2",
"@tailwindcss/vite": "4.3.3",
"@tanstack/react-query": "5.101.4",
"@types/shell-quote": "1.7.5",
@@ -45,14 +45,14 @@
"isbot": "5.1.39",
"lucide-react": "1.25.0",
"monaco-editor": "0.56.0",
"posthog-js": "1.372.6",
"posthog-js": "1.380.0",
"react": "19.2.8",
"react-dom": "19.2.8",
"react-hot-toast": "2.6.0",
"react-i18next": "17.0.11",
"react-icons": "5.6.0",
"react-markdown": "10.1.0",
"react-router": "7.17.0",
"react-router": "7.18.2",
"react-syntax-highlighter": "16.1.1",
"rehype-raw": "7.0.0",
"rehype-sanitize": "6.0.0",
@@ -127,7 +127,7 @@
"@eslint/js": "9.39.4",
"@mswjs/socket.io-binding": "0.2.0",
"@playwright/test": "1.62.0",
"@react-router/dev": "7.17.0",
"@react-router/dev": "7.18.2",
"@stryker-mutator/core": "9.6.1",
"@stryker-mutator/vitest-runner": "9.6.1",
"@tailwindcss/typography": "0.5.20",
@@ -147,7 +147,7 @@
"@vitest/coverage-v8": "4.1.10",
"cross-env": "10.1.0",
"electron": "42.3.3",
"electron-builder": "26.8.1",
"electron-builder": "26.15.3",
"eslint": "9.39.4",
"eslint-config-prettier": "10.1.8",
"eslint-import-resolver-typescript": "4.4.5",
@@ -183,7 +183,10 @@
"@vercel/static-config": {
"ajv": "8.20.0"
},
"dompurify": "3.4.7"
"dompurify": "3.4.12",
"typed-rest-client": {
"qs": "6.15.3"
}
},
"main": "./dist/index.cjs",
"module": "./dist/index.js",
@@ -242,6 +245,6 @@
"peerDependencies": {
"react": "19.2.8",
"react-dom": "19.2.8",
"react-router": "7.17.0"
"react-router": "7.18.2"
}
}
+21 -9
View File
@@ -7,8 +7,8 @@
* - Please do NOT modify this file.
*/
const PACKAGE_VERSION = '2.14.2'
const INTEGRITY_CHECKSUM = '4db4a41e972cec1b64cc569c66952d82'
const PACKAGE_VERSION = '2.15.0'
const INTEGRITY_CHECKSUM = '03cb67ac84128e63d7cd722a6e5b7f1e'
const IS_MOCKED_RESPONSE = Symbol('isMockedResponse')
const activeClientIds = new Set()
@@ -137,8 +137,18 @@ async function handleRequest(event, requestId, requestInterceptedAt) {
if (client && activeClientIds.has(client.id)) {
const serializedRequest = await serializeRequest(requestCloneForEvents)
// Omit the body of server-sent event stream responses.
// Cloning such responses would prevent client-side stream cancelations
// from reaching the original stream (a teed stream only cancels its
// source once both of its branches cancel) and would buffer the
// entire stream into the unconsumed clone indefinitely.
const isEventStreamResponse = response.headers
.get('content-type')
?.toLowerCase()
.startsWith('text/event-stream')
// Clone the response so both the client and the library could consume it.
const responseClone = response.clone()
const responseClone = isEventStreamResponse ? null : response.clone()
sendToClient(
client,
@@ -151,15 +161,17 @@ async function handleRequest(event, requestId, requestInterceptedAt) {
...serializedRequest,
},
response: {
type: responseClone.type,
status: responseClone.status,
statusText: responseClone.statusText,
headers: Object.fromEntries(responseClone.headers.entries()),
body: responseClone.body,
type: response.type,
status: response.status,
statusText: response.statusText,
headers: Object.fromEntries(response.headers.entries()),
body: responseClone ? responseClone.body : null,
},
},
},
responseClone.body ? [serializedRequest.body, responseClone.body] : [],
responseClone && responseClone.body
? [serializedRequest.body, responseClone.body]
: [],
)
}