mirror of
https://github.com/jamiepine/voicebox.git
synced 2026-10-03 17:15:19 -07:00
fix: force seroval 1.5.3 via bun overrides so @tanstack/router-core picks it up
Adding seroval as a direct root dependency left the lockfile's @tanstack/router-core/seroval entry pinned at the vulnerable 1.5.0, so the only real consumer was still bundling the CVE-2026-59940 version. A bun 'overrides' entry forces every resolution to 1.5.3 and drops the unused direct dependency.
This commit is contained in:
committed by
capy-ai-staging[bot]
parent
84900d4e86
commit
fc0bec8faf
+3
-1
@@ -44,7 +44,9 @@
|
||||
"packageManager": "[email protected]",
|
||||
"dependencies": {
|
||||
"loaders.css": "^0.1.2",
|
||||
"react-loaders": "^3.0.1",
|
||||
"react-loaders": "^3.0.1"
|
||||
},
|
||||
"overrides": {
|
||||
"seroval": "1.5.3"
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user