Files
supabase/pnpm-workspace.yaml
Ivan Vasilov d7626c9830 chore: Bump vulnerable dependencies (#42416)
This PR fixes:
- https://github.com/supabase/supabase/security/dependabot/2721
- https://github.com/supabase/supabase/security/dependabot/2699
- https://github.com/supabase/supabase/security/dependabot/2704
- https://github.com/supabase/supabase/security/dependabot/2701
- https://github.com/supabase/supabase/security/dependabot/2708
- https://github.com/supabase/supabase/security/dependabot/2709
- https://github.com/supabase/supabase/security/dependabot/2732
- https://github.com/supabase/supabase/security/dependabot/2733
- https://github.com/supabase/supabase/security/dependabot/2750
- https://github.com/supabase/supabase/security/dependabot/2751

It also dedupes `mermaid` and `sharp` deps.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Updated image-processing dependency to a newer patch release for
stability.
* Upgraded framework runtime to a minor release for improvements and bug
fixes.
  * Adjusted workspace dependency override for a transitive package.
* Added a development build tool dependency to the web app for improved
tooling.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-02-03 15:23:30 +01:00

88 lines
1.7 KiB
YAML

packages:
- apps/*
- packages/*
- blocks/*
- e2e/*
catalog:
'@sentry/nextjs': ^10.26.0
'@supabase/auth-js': 2.93.2
'@supabase/postgrest-js': 2.93.2
'@supabase/realtime-js': 2.93.2
'@supabase/supabase-js': 2.93.2
'@types/node': ^22.0.0
'@types/react': ^18.3.0
'@types/react-dom': ^18.3.0
next: ^15.5.10
lodash-es: ^4.17.23
lodash: ^4.17.23
react: ^18.3.0
react-dom: ^18.3.0
recharts: ^2.15.4
tailwindcss: 3.4.1
tsx: 4.20.3
typescript: ~5.9.0
valtio: ^1.12.0
vite: ^7.1.11
vitest: ^3.2.0
zod: 3.25.76
ignoredBuiltDependencies:
- '@parcel/watcher'
- '@sentry/cli'
- contentlayer2
- core-js
- es5-ext
- esbuild
- libpg-query
- msw
- node-pty
- protobufjs
- sharp
minimumReleaseAge: 10080
minimumReleaseAgeExclude:
- '@ai-sdk/*'
- '@supabase/*'
- 'next'
- '@next/*'
- ai
- js-yaml
- supabase
- iceberg-js
- '@vitejs/plugin-rsc'
- stripe-experiment-sync # TODO(matlin) remove, temp just to unblock launch
- braintrust
- tar
- diff
- lodash-es
- lodash
onlyBuiltDependencies:
- supabase
overrides:
'@eslint/eslintrc>js-yaml': ^4.1.1
'@nuxt/devtools-wizard>diff': ^8.0.3
'@react-router/dev>vite-node': 3.2.4
'@redocly/respect-core>form-data': ^4.0.4
'@redocly/respect-core>js-yaml': ^4.1.1
'@tanstack/directive-functions-plugin>vite': 'catalog:'
'@tanstack/react-start-plugin>vite': 'catalog:'
'@tanstack/start-server-core>h3': ^1.15.5
'@tanstack/react-start-server>h3': ^1.15.5
'@smithy/config-resolver': ^4.4.0
esbuild: ^0.25.2
nodemailer: ^7.0.11
lodash-es: 'catalog:'
lodash: 'catalog:'
payload>undici: ^7.18.2
preact: 10.26.10
refractor>prismjs: ^1.30.0
shadcn>diff: ^8.0.3
tar: ^7.5.7
tmp: ^0.2.4
vinxi>vite: 'catalog:'
vinxi>h3: ^1.15.5