mirror of
https://github.com/Wei-Shaw/sub2api.git
synced 2026-10-07 17:08:33 +08:00
新披露两条 high 级公告命中锁文件里的 postcss@8.5.6,frontend-security 的 audit exception 检查失败: - GHSA-6g55-p6wh-862q(2026-07-23 披露,修复版 8.5.12) CSS 注释中攻击者可控的 sourceMappingURL 导致任意文件读取与信息泄露 - GHSA-r28c-9q8g-f849(2026-07-24 披露,修复版 8.5.18) Previous Source Map 自动加载存在路径穿越,导致任意 .map 文件泄露 postcss 不只是 devDependency —— 它经 vue → @vue/compiler-sfc 进入生产依赖树, 因此 `pnpm audit --prod` 会命中。用 pnpm.overrides 而非只升直接依赖,可保证 所有引入路径的实例都被抬到修复版(沿用本仓 form-data@<4.0.6 的既有写法)。 锁文件用 pnpm 10 重新解析以匹配现有锁文件的生成工具,避免 pnpm 9 误删 11 处 libc: [glibc|musl] 平台门控字段;lockfileVersion 保持 9.0。 实际解析到 postcss 8.5.23,nanoid 3.3.11→3.3.16 是 postcss 自身依赖的 补丁级跟随,diff 无其他无关变动。 验证:复现 CI 失败步骤(pnpm audit --prod --audit-level=high + tools/check_pnpm_audit_exceptions.py)已通过;CI 所用 pnpm 9 的 --frozen-lockfile 接受该锁文件;vue-tsc --noEmit、pnpm build、vitest 均通过。
70 lines
1.9 KiB
JSON
70 lines
1.9 KiB
JSON
{
|
|
"name": "sub2api-frontend",
|
|
"private": true,
|
|
"version": "1.0.0",
|
|
"type": "module",
|
|
"scripts": {
|
|
"dev": "vite",
|
|
"build": "vue-tsc -b && vite build",
|
|
"preview": "vite preview",
|
|
"lint": "eslint . --ext .vue,.js,.jsx,.cjs,.mjs,.ts,.tsx,.cts,.mts --fix",
|
|
"lint:check": "eslint . --ext .vue,.js,.jsx,.cjs,.mjs,.ts,.tsx,.cts,.mts",
|
|
"typecheck": "vue-tsc --noEmit",
|
|
"test": "vitest",
|
|
"test:run": "vitest run",
|
|
"test:coverage": "vitest run --coverage"
|
|
},
|
|
"dependencies": {
|
|
"@airwallex/components-sdk": "^1.30.2",
|
|
"@lobehub/icons": "^4.0.2",
|
|
"@stripe/stripe-js": "^9.0.1",
|
|
"@tanstack/vue-virtual": "^3.13.23",
|
|
"@vueuse/core": "^10.7.0",
|
|
"axios": "^1.18.0",
|
|
"chart.js": "^4.4.1",
|
|
"dompurify": "^3.3.1",
|
|
"driver.js": "^1.4.0",
|
|
"file-saver": "^2.0.5",
|
|
"marked": "^17.0.1",
|
|
"pinia": "^2.1.7",
|
|
"qrcode": "^1.5.4",
|
|
"vue": "^3.4.0",
|
|
"vue-chartjs": "^5.3.0",
|
|
"vue-draggable-plus": "^0.6.1",
|
|
"vue-i18n": "^9.14.5",
|
|
"vue-router": "^4.2.5",
|
|
"xlsx": "^0.18.5"
|
|
},
|
|
"devDependencies": {
|
|
"@intlify/message-compiler": "9.14.5",
|
|
"@types/dompurify": "^3.0.5",
|
|
"@types/file-saver": "^2.0.7",
|
|
"@types/mdx": "^2.0.13",
|
|
"@types/node": "^20.10.5",
|
|
"@types/qrcode": "^1.5.6",
|
|
"@typescript-eslint/eslint-plugin": "^7.18.0",
|
|
"@typescript-eslint/parser": "^7.18.0",
|
|
"@vitejs/plugin-vue": "^5.2.3",
|
|
"@vitest/coverage-v8": "^2.1.9",
|
|
"@vue/test-utils": "^2.4.6",
|
|
"autoprefixer": "^10.4.16",
|
|
"eslint": "^8.57.0",
|
|
"eslint-plugin-vue": "^9.25.0",
|
|
"jsdom": "^24.1.3",
|
|
"postcss": "^8.4.32",
|
|
"tailwindcss": "^3.4.0",
|
|
"typescript": "~5.6.0",
|
|
"vite": "^5.0.10",
|
|
"vite-plugin-checker": "^0.9.1",
|
|
"vitest": "^2.1.9",
|
|
"vue-tsc": "^2.2.0"
|
|
},
|
|
"pnpm": {
|
|
"overrides": {
|
|
"js-cookie": "3.0.7",
|
|
"form-data@<4.0.6": ">=4.0.6",
|
|
"postcss@<8.5.18": ">=8.5.18"
|
|
}
|
|
}
|
|
}
|