fix: force seroval 1.5.3 via bun overrides so @tanstack/router-core picks it up

Adding seroval as a direct root dependency left the lockfile's
@tanstack/router-core/seroval entry pinned at the vulnerable 1.5.0, so the
only real consumer was still bundling the CVE-2026-59940 version. A bun
'overrides' entry forces every resolution to 1.5.3 and drops the unused
direct dependency.
This commit is contained in:
jamiepine
2026-10-04 00:00:47 +00:00
committed by capy-ai-staging[bot]
parent 84900d4e86
commit fc0bec8faf
2 changed files with 6 additions and 6 deletions
+3 -1
View File
@@ -44,7 +44,9 @@
"packageManager": "[email protected]",
"dependencies": {
"loaders.css": "^0.1.2",
"react-loaders": "^3.0.1",
"react-loaders": "^3.0.1"
},
"overrides": {
"seroval": "1.5.3"
}
}