fix(website): pin brace-expansion and fast-uri past new advisories (#2019)

Security's docs-site audit went red on main after four advisories landed
in the site's dev-only serve dependency chain. Raise the site's existing
overrides so they resolve patched versions.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Clay Good
2026-09-30 23:24:14 +00:00
committed by GitHub
co-authored by Claude Opus 5.5
parent 94ca9c1eb1
commit 3a34ea309d
2 changed files with 16 additions and 12 deletions
+10 -10
View File
@@ -7,8 +7,8 @@ settings:
overrides:
postcss: ^8.5.28
sharp: ^0.35.3
brace-expansion@<=5.0.8: '>=5.0.9 <6'
fast-uri@<3.1.6: ^3.1.6
brace-expansion@<5.0.12: '>=5.0.12 <6'
fast-uri@<3.1.8: ^3.1.8
nanoid@<3.3.17: '>=3.3.17 <4'
importers:
@@ -1171,8 +1171,8 @@ packages:
resolution: {integrity: sha512-j//dBVuyacJbvW+tvZ9HuH03fZ46QcaKvvhZickZqtB271DxJ7SNRSNxrV/dZX0085m7hISRZWbzWlJvx/rHSg==}
engines: {node: '>=14.16'}
brace-expansion@5.0.9:
resolution: {integrity: sha512-ScQ4IuvIEF1TMlP7Zt+vjJ//9zlPb2SDcxWxM3bk8s6t6GGdJ7KO1dCcTidOPJKePW30LE/2cT7wCyPho9/Wxg==}
brace-expansion@5.0.12:
resolution: {integrity: sha512-YovQ3rzhaLMIrDjNDMkNS01tea93qhEhG5xy8f6+R0l+dw3Ki+5sCoIoI942iuLZTHWogWktgwVDhU09iNEimQ==}
engines: {node: 20 || >=22}
bytes@3.0.0:
@@ -1390,8 +1390,8 @@ packages:
fast-deep-equal@3.1.3:
resolution: {integrity: sha512-f3qQ9oQy9j2AhBe/H9VC91wLmKBCCU/gDOnKNAYG5hswO7BLKj09Hc5HYNz9cGI++xlpDCIgDaitVs03ATR84Q==}
fast-uri@3.1.7:
resolution: {integrity: sha512-dOvZVzjdZdz7phd9v6jCbwxrBW3fK6n8Rc0CtdmM4bumzMnxywBYhuph6J819RRw/ku+rLbelwfMunktuzVVHg==}
fast-uri@3.1.8:
resolution: {integrity: sha512-GZMtZUTNRpOVIECoXwLNZS5xUGE+mVNbTB8h/7Rwh2TFWcBQiPzTgyZi05BF9UMZKkLJv8XBRJTlU7zg8+ZfMg==}
fdir@6.5.0:
resolution: {integrity: sha512-tIbYtZbucOs0BRGqPJkshJUYdL+SDH7dVM8gjy+ERp3WAUjLEFJE+02kanyHtwjWOnwrKYBiwAmM0p4kLJAnXg==}
@@ -3234,7 +3234,7 @@ snapshots:
ajv@8.18.0:
dependencies:
fast-deep-equal: 3.1.3
fast-uri: 3.1.7
fast-uri: 3.1.8
json-schema-traverse: 1.0.0
require-from-string: 2.0.2
@@ -3284,7 +3284,7 @@ snapshots:
widest-line: 4.0.1
wrap-ansi: 8.1.0
brace-expansion@5.0.9:
brace-expansion@5.0.12:
dependencies:
balanced-match: 4.0.4
@@ -3516,7 +3516,7 @@ snapshots:
fast-deep-equal@3.1.3: {}
fast-uri@3.1.7: {}
fast-uri@3.1.8: {}
fdir@6.5.0(picomatch@4.0.7):
optionalDependencies:
@@ -4301,7 +4301,7 @@ snapshots:
minimatch@3.1.5:
dependencies:
brace-expansion: 5.0.9
brace-expansion: 5.0.12
minimist@1.2.8: {}
+6 -2
View File
@@ -12,8 +12,12 @@ allowBuilds:
overrides:
postcss: ^8.5.28
sharp: ^0.35.3
brace-expansion@<=5.0.8: '>=5.0.9 <6'
fast-uri@<3.1.6: ^3.1.6
# GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7, GHSA-q2hr-2g5m-vwhr — brace-expansion
# DoS via nested or comma-heavy brace groups. Dev-only (serve > serve-handler >
# minimatch); never in the static site.
brace-expansion@<5.0.12: '>=5.0.12 <6'
# GHSA-hrr3-gc8f-f4qj — fast-uri. Dev-only (serve > ajv).
fast-uri@<3.1.8: ^3.1.8
# GHSA-2v37-7h3g-55p8 / CVE-2026-67213 — nanoid infinite loop on size=0. Build-time
# only (transitive via postcss); this is a statically exported site with no server
# runtime. Remove once transitive nanoid is >=3.3.17 (check: pnpm why nanoid).