[SECVULN-37949] UI: add pnpm overrides for ajv and markdown-it libraries to address open security vulns (#12559) (#12590)

Co-authored-by: Shannon Roberts (Beagin) <beagins@users.noreply.github.com>
This commit is contained in:
Vault Automation 2026-02-26 17:19:25 -07:00 committed by GitHub
parent 5f77aa78fc
commit 8f1019d4e7
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
2 changed files with 83 additions and 61 deletions

View File

@ -178,6 +178,8 @@
"@babel/runtime": "7.27.0",
"@embroider/macros": "1.15.0",
"@messageformat/runtime": "3.0.2",
"ajv@6.12.6": "6.14.0",
"ajv@8.17.1": "8.18.0",
"ansi-html": "0.0.8",
"async": "2.6.4",
"braces": "3.0.3",
@ -187,6 +189,7 @@
"ini": "1.3.8",
"json5": "1.0.2",
"kind-of": "6.0.3",
"markdown-it": "14.1.1",
"micromatch": "4.0.8",
"prismjs": "1.30.0",
"qs": "6.14.1",

141
ui/pnpm-lock.yaml generated
View File

@ -8,6 +8,8 @@ overrides:
'@babel/runtime': 7.27.0
'@embroider/macros': 1.15.0
'@messageformat/runtime': 3.0.2
ajv@6.12.6: 6.14.0
ajv@8.17.1: 8.18.0
ansi-html: 0.0.8
async: 2.6.4
braces: 3.0.3
@ -17,6 +19,7 @@ overrides:
ini: 1.3.8
json5: 1.0.2
kind-of: 6.0.3
markdown-it: 14.1.1
micromatch: 4.0.8
prismjs: 1.30.0
qs: 6.14.1
@ -2310,18 +2313,18 @@ packages:
ajv-keywords@3.5.2:
resolution: {integrity: sha512-5p6WTN0DdTGVQk6VjcEju19IgaHudalcfabD7yhDGeA6bcQnmL+CpveLJq/3hvfwd1aof6L386Ougkx6RfyMIQ==}
peerDependencies:
ajv: ^6.9.1
ajv: 6.14.0
ajv-keywords@5.1.0:
resolution: {integrity: sha512-YCS/JNFAUyr5vAuhk1DWm1CBxRHW9LbJ2ozWeemrIqpbsqKjHVxYPyi5GC0rjZIT5JxJ3virVTS8wk4i/Z+krw==}
peerDependencies:
ajv: ^8.8.2
ajv: 8.18.0
ajv@6.12.6:
resolution: {integrity: sha512-j3fVLgvTo527anyYyJOGTYJbG+vnnQYvE0m5mmkc1TK+nxAppkCLMIL0aZ4dblVCNoGShhm+kzE4ZUykBoMg4g==}
ajv@6.14.0:
resolution: {integrity: sha512-IWrosm/yrn43eiKqkfkHis7QioDleaXQHdDVPKg0FSwwd/DuvyX79TZnFOnYpB7dcsFAMmtFztZuXPDvSePkFw==}
ajv@8.17.1:
resolution: {integrity: sha512-B/gBuNg5SiMTrPkC+A2+cW0RszwxYmn6VYxB/inlBStS5nx6xHIt/ehKRhIMhqusl7a8LjQoZnjCs5vhwxOQ1g==}
ajv@8.18.0:
resolution: {integrity: sha512-PlXPeEWMXMZ7sPYOHqmDyCJzcfNrUr3fGNKtezX14ykXOEIvyK81d+qydx89KY5O71FKMPaQ2vBfBFI5NHR63A==}
amd-name-resolver@0.0.6:
resolution: {integrity: sha512-W2trar3LgeKV/yB6ZRD3Iw7MlhrKjLMVSNAatWNNYsn4w+iSfbmA66VB+jQjVIfvzHPZicnHObAvflMkoVtjAQ==}
@ -5752,9 +5755,6 @@ packages:
lines-and-columns@1.2.4:
resolution: {integrity: sha512-7ylylesZQ/PV29jhEDl3Ufjo6ZX7gCqJr5F7PKrqc93v7fzSymt1BpwEU8nAUXs8qzzvqhbjhK5QZg6Mt/HkBg==}
linkify-it@4.0.1:
resolution: {integrity: sha512-C7bfi1UZmoj8+PQx22XyeXCuBlokoyWQL5pWSP+EI6nzRylyThouddufc2c1NDIcP9k5agmN9fLpA7VNJfIiqw==}
linkify-it@5.0.0:
resolution: {integrity: sha512-5aHCbzQRADcdP+ATqnDuhhJ/MRIqDkZX5pyjFHRRysS8vZ5AbqGEoFIb6pYHPZ+L/OC2Lc+xT8uHVVR5CAK/wQ==}
@ -5941,19 +5941,15 @@ packages:
resolution: {integrity: sha512-FlCHFwNnutLgVTflOYHPW2pPcl2AACqVzExlkGQNsi4CJgqOHN7YTgDd4LuhgN1BFO3TS0vLAruV1Td6dwWPJA==}
peerDependencies:
'@types/markdown-it': '*'
markdown-it: '*'
markdown-it: 14.1.1
markdown-it-terminal@0.4.0:
resolution: {integrity: sha512-NeXtgpIK6jBciHTm9UhiPnyHDdqyVIdRPJ+KdQtZaf/wR74gvhCNbw5li4TYsxRp5u3ZoHEF4DwpECeZqyCw+w==}
peerDependencies:
markdown-it: '>= 13.0.0'
markdown-it: 14.1.1
markdown-it@13.0.2:
resolution: {integrity: sha512-FtwnEuuK+2yVU7goGn/MJ0WBZMM9ZPgU9spqlFs7/A/pDIUNSOQZhUgOqYCficIuR2QaFnrt8LHqBWsbTAoI5w==}
hasBin: true
markdown-it@14.1.0:
resolution: {integrity: sha512-a54IwgWPaeBCAAsv13YgmALOF1elABB08FxO9i+r4VFk5Vl4pKokRPeX8u5TCgSsPi6ec1otfLjdOpVcgbpshg==}
markdown-it@14.1.1:
resolution: {integrity: sha512-BuU2qnTti9YKgK5N+IeMubp14ZUKUUw7yeJbkjtosvHiP0AZ5c8IAgEMk79D0eC8F23r4Ac/q8cAIFdm2FtyoA==}
hasBin: true
markdown-table@2.0.0:
@ -7830,9 +7826,6 @@ packages:
resolution: {integrity: sha512-ya4mg/30vm+DOWfBg4YK3j2WD6TWtRkCbasOJr40CseYENzCUby/7rIvXA99JGsQHeNxLbnXdyLLxKSv3tauFw==}
engines: {node: '>=12.17'}
uc.micro@1.0.6:
resolution: {integrity: sha512-8Y75pvTYkLJW2hWQHXxoqRgV7qb9B+9vFEtidML+7koHUFapnVJAZ6cKs+Qjz5Aw3aZWHMC6u0wJE3At+nSGwA==}
uc.micro@2.1.0:
resolution: {integrity: sha512-ARDJmphmdvUk6Glw7y9DQ2bFkKBHwQHLi2lsaH6PPmz/Ka9sFOBsBluozhDltWmnv9u/cF6Rt87znRTPV+yp/A==}
@ -10252,7 +10245,7 @@ snapshots:
'@eslint/eslintrc@2.1.4':
dependencies:
ajv: 6.12.6
ajv: 6.14.0
debug: 4.4.1
espree: 9.6.1
globals: 13.24.0
@ -11071,6 +11064,26 @@ snapshots:
- '@babel/core'
- supports-color
'@types/ember@4.0.11':
dependencies:
'@types/ember__application': 4.0.11(@babel/core@7.26.10)
'@types/ember__array': 4.0.10(@babel/core@7.26.10)
'@types/ember__component': 4.0.22
'@types/ember__controller': 4.0.12(@babel/core@7.26.10)
'@types/ember__debug': 4.0.8(@babel/core@7.26.10)
'@types/ember__engine': 4.0.11(@babel/core@7.26.10)
'@types/ember__error': 4.0.6
'@types/ember__object': 4.0.12(@babel/core@7.26.10)
'@types/ember__polyfills': 4.0.6
'@types/ember__routing': 4.0.22
'@types/ember__runloop': 4.0.10
'@types/ember__service': 4.0.9(@babel/core@7.26.10)
'@types/ember__string': 3.16.3
'@types/ember__template': 4.0.7
'@types/ember__test': 4.0.6(@babel/core@7.26.10)
'@types/ember__utils': 4.0.7
'@types/rsvp': 4.0.9
'@types/ember@4.0.11(@babel/core@7.26.10)':
dependencies:
'@types/ember__application': 4.0.11(@babel/core@7.26.10)
@ -11097,11 +11110,11 @@ snapshots:
'@types/ember__application@4.0.11(@babel/core@7.26.10)':
dependencies:
'@glimmer/component': 1.1.2(@babel/core@7.26.10)
'@types/ember': 4.0.11(@babel/core@7.26.10)
'@types/ember': 4.0.11
'@types/ember__engine': 4.0.11(@babel/core@7.26.10)
'@types/ember__object': 4.0.12(@babel/core@7.26.10)
'@types/ember__owner': 4.0.9
'@types/ember__routing': 4.0.22(@babel/core@7.26.10)
'@types/ember__routing': 4.0.22
transitivePeerDependencies:
- '@babel/core'
- supports-color
@ -11114,6 +11127,11 @@ snapshots:
- '@babel/core'
- supports-color
'@types/ember__component@4.0.22':
dependencies:
'@types/ember': 4.0.11
'@types/ember__object': 4.0.12(@babel/core@7.26.10)
'@types/ember__component@4.0.22(@babel/core@7.26.10)':
dependencies:
'@types/ember': 4.0.11(@babel/core@7.26.10)
@ -11159,6 +11177,13 @@ snapshots:
'@types/ember__polyfills@4.0.6': {}
'@types/ember__routing@4.0.22':
dependencies:
'@types/ember': 4.0.11
'@types/ember__controller': 4.0.12(@babel/core@7.26.10)
'@types/ember__object': 4.0.12(@babel/core@7.26.10)
'@types/ember__service': 4.0.9(@babel/core@7.26.10)
'@types/ember__routing@4.0.22(@babel/core@7.26.10)':
dependencies:
'@types/ember': 4.0.11(@babel/core@7.26.10)
@ -11169,6 +11194,10 @@ snapshots:
- '@babel/core'
- supports-color
'@types/ember__runloop@4.0.10':
dependencies:
'@types/ember': 4.0.11
'@types/ember__runloop@4.0.10(@babel/core@7.26.10)':
dependencies:
'@types/ember': 4.0.11(@babel/core@7.26.10)
@ -11196,6 +11225,10 @@ snapshots:
- '@babel/core'
- supports-color
'@types/ember__utils@4.0.7':
dependencies:
'@types/ember': 4.0.11
'@types/ember__utils@4.0.7(@babel/core@7.26.10)':
dependencies:
'@types/ember': 4.0.11(@babel/core@7.26.10)
@ -11605,25 +11638,25 @@ snapshots:
ajv-formats@2.1.1:
dependencies:
ajv: 8.17.1
ajv: 8.18.0
ajv-keywords@3.5.2(ajv@6.12.6):
ajv-keywords@3.5.2(ajv@6.14.0):
dependencies:
ajv: 6.12.6
ajv: 6.14.0
ajv-keywords@5.1.0(ajv@8.17.1):
ajv-keywords@5.1.0(ajv@8.18.0):
dependencies:
ajv: 8.17.1
ajv: 8.18.0
fast-deep-equal: 3.1.3
ajv@6.12.6:
ajv@6.14.0:
dependencies:
fast-deep-equal: 3.1.3
fast-json-stable-stringify: 2.1.0
json-schema-traverse: 0.4.1
uri-js: 4.4.1
ajv@8.17.1:
ajv@8.18.0:
dependencies:
fast-deep-equal: 3.1.3
fast-uri: 3.0.6
@ -14037,8 +14070,8 @@ snapshots:
is-language-code: 3.1.0
isbinaryfile: 5.0.4
lodash: 4.17.23
markdown-it: 13.0.2
markdown-it-terminal: 0.4.0(markdown-it@13.0.2)
markdown-it: 14.1.1
markdown-it-terminal: 0.4.0(markdown-it@14.1.1)
minimatch: 7.4.6
morgan: 1.10.0
nopt: 3.0.6
@ -14896,7 +14929,7 @@ snapshots:
'@humanwhocodes/module-importer': 1.0.1
'@nodelib/fs.walk': 1.2.8
'@ungap/structured-clone': 1.3.0
ajv: 6.12.6
ajv: 6.14.0
chalk: 4.1.2
cross-spawn: 7.0.6
debug: 4.4.1
@ -16257,8 +16290,8 @@ snapshots:
escape-string-regexp: 2.0.0
js2xmlparser: 4.0.2
klaw: 3.0.0
markdown-it: 14.1.0
markdown-it-anchor: 8.6.7(@types/markdown-it@14.1.2)(markdown-it@14.1.0)
markdown-it: 14.1.1
markdown-it-anchor: 8.6.7(@types/markdown-it@14.1.2)(markdown-it@14.1.1)
marked: 4.3.0
mkdirp: 1.0.4
requizzle: 0.2.4
@ -16369,10 +16402,6 @@ snapshots:
lines-and-columns@1.2.4: {}
linkify-it@4.0.1:
dependencies:
uc.micro: 1.0.6
linkify-it@5.0.0:
dependencies:
uc.micro: 2.1.0
@ -16558,28 +16587,20 @@ snapshots:
map-obj@4.3.0: {}
markdown-it-anchor@8.6.7(@types/markdown-it@14.1.2)(markdown-it@14.1.0):
markdown-it-anchor@8.6.7(@types/markdown-it@14.1.2)(markdown-it@14.1.1):
dependencies:
'@types/markdown-it': 14.1.2
markdown-it: 14.1.0
markdown-it: 14.1.1
markdown-it-terminal@0.4.0(markdown-it@13.0.2):
markdown-it-terminal@0.4.0(markdown-it@14.1.1):
dependencies:
ansi-styles: 3.2.1
cardinal: 1.0.0
cli-table: 0.3.11
lodash.merge: 4.6.2
markdown-it: 13.0.2
markdown-it: 14.1.1
markdown-it@13.0.2:
dependencies:
argparse: 2.0.1
entities: 3.0.1
linkify-it: 4.0.1
mdurl: 1.0.1
uc.micro: 1.0.6
markdown-it@14.1.0:
markdown-it@14.1.1:
dependencies:
argparse: 2.0.1
entities: 4.5.0
@ -17849,21 +17870,21 @@ snapshots:
schema-utils@2.7.1:
dependencies:
'@types/json-schema': 7.0.15
ajv: 6.12.6
ajv-keywords: 3.5.2(ajv@6.12.6)
ajv: 6.14.0
ajv-keywords: 3.5.2(ajv@6.14.0)
schema-utils@3.3.0:
dependencies:
'@types/json-schema': 7.0.15
ajv: 6.12.6
ajv-keywords: 3.5.2(ajv@6.12.6)
ajv: 6.14.0
ajv-keywords: 3.5.2(ajv@6.14.0)
schema-utils@4.3.2:
dependencies:
'@types/json-schema': 7.0.15
ajv: 8.17.1
ajv: 8.18.0
ajv-formats: 2.1.1
ajv-keywords: 5.1.0(ajv@8.17.1)
ajv-keywords: 5.1.0(ajv@8.18.0)
semver@5.7.2: {}
@ -18376,7 +18397,7 @@ snapshots:
table@6.9.0:
dependencies:
ajv: 8.17.1
ajv: 8.18.0
lodash.truncate: 4.4.2
slice-ansi: 4.0.0
string-width: 4.2.3
@ -18734,8 +18755,6 @@ snapshots:
typical@7.3.0: {}
uc.micro@1.0.6: {}
uc.micro@2.1.0: {}
uglify-js@3.19.3: