Skip to content

Commit 9463a57

Browse files
committed
chore(security): update vulnerable transitive dependencies
Update transitive dependencies to address known CVEs: - semver 7.5.0 → 7.7.4 (CVE-2022-25883 ReDoS) - ws 8.11.0 → 8.19.0 (CVE-2024-37890 DoS via headers) - minimatch 10.0.1 → 10.2.4 (multiple ReDoS CVEs) - tar 7.5.4 → 7.5.11 (multiple path traversal CVEs) Packages updated: - apps/webapp: semver, ws - packages/cli-v3: minimatch, semver, tar, ws - packages/trigger-sdk: ws Test results: - @trigger.dev/core: 412/412 passed - @trigger.dev/sdk: 10/10 passed - 7/8 package test suites passed (redis-worker requires testcontainers/Docker environment, not affected by these changes)
1 parent c0b6309 commit 9463a57

File tree

4 files changed

+323
-258
lines changed

4 files changed

+323
-258
lines changed

apps/webapp/package.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,6 @@
5454
"@electric-sql/react": "^0.3.5",
5555
"@headlessui/react": "^1.7.8",
5656
"@heroicons/react": "^2.0.12",
57-
"@jsonhero/schema-infer": "^0.1.5",
5857
"@internal/cache": "workspace:*",
5958
"@internal/redis": "workspace:*",
6059
"@internal/run-engine": "workspace:*",
@@ -63,6 +62,7 @@
6362
"@internal/tsql": "workspace:*",
6463
"@internal/zod-worker": "workspace:*",
6564
"@internationalized/date": "^3.5.1",
65+
"@jsonhero/schema-infer": "^0.1.5",
6666
"@kapaai/react-sdk": "^0.1.3",
6767
"@lezer/highlight": "^1.1.6",
6868
"@opentelemetry/api": "1.9.0",
@@ -204,7 +204,7 @@
204204
"remix-typedjson": "0.3.1",
205205
"remix-utils": "^7.7.0",
206206
"seedrandom": "^3.0.5",
207-
"semver": "^7.5.0",
207+
"semver": "^7.7.4",
208208
"simple-oauth2": "^5.0.0",
209209
"simplur": "^3.0.1",
210210
"slug": "^6.0.0",
@@ -223,7 +223,7 @@
223223
"ulid": "^2.3.0",
224224
"ulidx": "^2.2.1",
225225
"uuid": "^9.0.0",
226-
"ws": "^8.11.0",
226+
"ws": "^8.19.0",
227227
"zod": "3.25.76",
228228
"zod-error": "1.5.0",
229229
"zod-validation-error": "^1.5.0"

packages/cli-v3/package.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -120,7 +120,7 @@
120120
"json-stable-stringify": "^1.3.0",
121121
"jsonc-parser": "3.2.1",
122122
"magicast": "^0.3.4",
123-
"minimatch": "^10.0.1",
123+
"minimatch": "^10.2.4",
124124
"mlly": "^1.7.1",
125125
"nypm": "^0.5.4",
126126
"object-hash": "^3.0.0",
@@ -131,18 +131,18 @@
131131
"pkg-types": "^1.1.3",
132132
"polka": "^0.5.2",
133133
"resolve": "^1.22.8",
134-
"semver": "^7.5.0",
134+
"semver": "^7.7.4",
135135
"signal-exit": "^4.1.0",
136136
"socket.io-client": "4.7.5",
137137
"source-map-support": "0.5.21",
138138
"std-env": "^3.7.0",
139139
"strip-ansi": "^7.1.0",
140140
"supports-color": "^10.0.0",
141-
"tar": "^7.5.4",
141+
"tar": "^7.5.11",
142142
"tiny-invariant": "^1.2.0",
143143
"tinyexec": "^0.3.1",
144144
"tinyglobby": "^0.2.10",
145-
"ws": "^8.18.0",
145+
"ws": "^8.19.0",
146146
"xdg-app-paths": "^8.3.0",
147147
"zod": "3.25.76",
148148
"zod-validation-error": "^1.5.0"

packages/trigger-sdk/package.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -61,7 +61,7 @@
6161
"ulid": "^2.3.0",
6262
"uncrypto": "^0.1.3",
6363
"uuid": "^9.0.0",
64-
"ws": "^8.11.0"
64+
"ws": "^8.19.0"
6565
},
6666
"devDependencies": {
6767
"@arethetypeswrong/cli": "^0.15.4",
@@ -78,8 +78,8 @@
7878
"zod": "3.25.76"
7979
},
8080
"peerDependencies": {
81-
"zod": "^3.0.0 || ^4.0.0",
82-
"ai": "^4.2.0 || ^5.0.0 || ^6.0.0"
81+
"ai": "^4.2.0 || ^5.0.0 || ^6.0.0",
82+
"zod": "^3.0.0 || ^4.0.0"
8383
},
8484
"peerDependenciesMeta": {
8585
"ai": {

0 commit comments

Comments
 (0)