From 9436ddc147ed91bd9f0240522528b6948bd65e04 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Alex=20Aveill=C3=A1n?= Date: Fri, 6 Mar 2026 13:59:52 +0100 Subject: [PATCH 1/9] fix: update transitive dependencies to resolve known vulnerabilities Non-breaking semver-compatible updates via npm audit fix: - tar 7.4.3 to 7.5.10 (High: path traversal, symlink poisoning, hardlink attacks) - lodash 4.17.21 to 4.17.23 (Moderate: prototype pollution in _.unset/_.omit) - js-yaml 3.14.1 to 3.14.2, 4.1.0 to 4.1.1 (Moderate: prototype pollution in merge) - glob 10.4.5 to 10.5.0 (High: command injection via --cmd) - brace-expansion 1.1.11 to 1.1.12, 2.0.1 to 2.0.2 (Low: ReDoS) - minimatch 3.1.2 to 3.1.5, 9.0.5 to 9.0.9, 5.1.6 to 9.0.9 (High: ReDoS) - mocha 11.4.0 to 11.7.5 (within ^11.4.0) - jshint 2.13.4 to 2.13.6 (within ^2.10.0) All updates stay within declared semver ranges. Only package-lock.json changed. Resolves 5 of 11 reported npm audit vulnerabilities. --- package-lock.json | 346 +++++++++++++++++++--------------------------- 1 file changed, 144 insertions(+), 202 deletions(-) diff --git a/package-lock.json b/package-lock.json index 93f2f440d..9188bb409 100644 --- a/package-lock.json +++ b/package-lock.json @@ -79,7 +79,6 @@ "integrity": "sha512-SRijHmF0PSPgLIBYlWnG0hyeJLwXE2CgpsXaMOrtt2yp9/86ALw6oUlj9KYuZ0JN07T4eBMVIW4li/9S1j2BGA==", "dev": true, "license": "MIT", - "peer": true, "dependencies": { "@ampproject/remapping": "^2.2.0", "@babel/code-frame": "^7.26.2", @@ -733,9 +732,10 @@ } }, "node_modules/aws-sdk": { - "version": "2.1692.0", - "resolved": "https://registry.npmjs.org/aws-sdk/-/aws-sdk-2.1692.0.tgz", - "integrity": "sha512-x511uiJ/57FIsbgUe5csJ13k3uzu25uWQE+XqfBis/sB0SFoiElJWXRkgEAUh0U6n40eT3ay5Ue4oPkRMu1LYw==", + "version": "2.1693.0", + "resolved": "https://registry.npmjs.org/aws-sdk/-/aws-sdk-2.1693.0.tgz", + "integrity": "sha512-cJmb8xEnVLT+R6fBS5sn/EFJiX7tUnDaPtOPZ1vFbOJtd0fnZn/Ky2XGgsvvoeliWeH7mL3TWSX5zXXGSQV6gQ==", + "deprecated": "The AWS SDK for JavaScript (v2) has reached end-of-support, and no longer receives updates. Please migrate your code to use AWS SDK for JavaScript (v3). More info https://a.co/cUPnyil", "dev": true, "hasInstallScript": true, "license": "Apache-2.0", @@ -859,10 +859,11 @@ ] }, "node_modules/brace-expansion": { - "version": "1.1.11", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.11.tgz", - "integrity": "sha512-iCuPHDFgrHX7H2vEI/5xpz07zSHB00TpugqhmYtVmMO6518mCuRMoOYFldEBl0g187ufozdaHgWKcYFb61qGiA==", + "version": "1.1.12", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.12.tgz", + "integrity": "sha512-9T9UjW3r0UW5c1Q7GTwllptXwhvYmEzFhzMfZ9H7FQWt+uZePjZPjBP/W1ZEyZ1twGWom5/56TF4lPcqjnDHcg==", "dev": true, + "license": "MIT", "dependencies": { "balanced-match": "^1.0.0", "concat-map": "0.0.1" @@ -894,7 +895,6 @@ } ], "license": "MIT", - "peer": true, "dependencies": { "caniuse-lite": "^1.0.30001688", "electron-to-chromium": "^1.5.73", @@ -952,9 +952,9 @@ } }, "node_modules/cacache/node_modules/brace-expansion": { - "version": "2.0.1", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.0.1.tgz", - "integrity": "sha512-XnAIvQ8eM+kC6aULx6wuQiwVsnzsi9d3WxzV3FpWTGA19F621kwdbsAcFKXgKUHZWsy+mY6iL1sHTxWEFCytDA==", + "version": "2.0.2", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.0.2.tgz", + "integrity": "sha512-Jt0vHyM+jmUBqojB7E1NIYadt0vI0Qxjxd2TErW94wDz+E2LAm5vKMXXwg6ZZBTHPuUlDgQHKXvjGBdfcF1ZDQ==", "license": "MIT", "dependencies": { "balanced-match": "^1.0.0" @@ -973,9 +973,10 @@ } }, "node_modules/cacache/node_modules/glob": { - "version": "10.4.5", - "resolved": "https://registry.npmjs.org/glob/-/glob-10.4.5.tgz", - "integrity": "sha512-7Bv8RF0k6xjo7d4A/PxYLbUCfb6c+Vpd2/mB2yRDlew7Jb5hEXiCD9ibfO7wpk8i4sevK6DFny9h7EYbM3/sHg==", + "version": "10.5.0", + "resolved": "https://registry.npmjs.org/glob/-/glob-10.5.0.tgz", + "integrity": "sha512-DfXN8DfhJ7NH3Oe7cFmu3NCu1wKbkReJ8TorzSAFbSKrlNaQSKfIzqYqVY8zlbs2NLBbWpRiU52GX2PbaBVNkg==", + "deprecated": "Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting i@izs.me", "license": "ISC", "dependencies": { "foreground-child": "^3.1.0", @@ -993,12 +994,12 @@ } }, "node_modules/cacache/node_modules/minimatch": { - "version": "9.0.5", - "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-9.0.5.tgz", - "integrity": "sha512-G6T0ZX48xgozx7587koeX9Ys2NYy6Gmv//P89sEte9V9whIapMNF4idKxnW2QtCcLiTWlb/wfCabAtAFWhhBow==", + "version": "9.0.9", + "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-9.0.9.tgz", + "integrity": "sha512-OBwBN9AL4dqmETlpS2zasx+vTeWclWzkblfZk7KTA5j3jeOONz/tRCnZomUyvNg83wL5Zv9Ss6HMJXAgL8R2Yg==", "license": "ISC", "dependencies": { - "brace-expansion": "^2.0.1" + "brace-expansion": "^2.0.2" }, "engines": { "node": ">=16 || 14 >=14.17" @@ -2493,18 +2494,6 @@ "node": ">= 14" } }, - "node_modules/iconv-lite": { - "version": "0.6.3", - "resolved": "https://registry.npmjs.org/iconv-lite/-/iconv-lite-0.6.3.tgz", - "integrity": "sha512-4fCk79wshMdzMp2rH06qWrJE4iolqLhCUH+OiuIgU++RB0+94NlDL81atO7GX55uUKueo0txHNtvEyI6D7WdMw==", - "optional": true, - "dependencies": { - "safer-buffer": ">= 2.1.2 < 3.0.0" - }, - "engines": { - "node": ">=0.10.0" - } - }, "node_modules/ieee754": { "version": "1.1.13", "resolved": "https://registry.npmjs.org/ieee754/-/ieee754-1.1.13.tgz", @@ -2684,6 +2673,16 @@ "node": ">=0.10.0" } }, + "node_modules/is-path-inside": { + "version": "3.0.3", + "resolved": "https://registry.npmjs.org/is-path-inside/-/is-path-inside-3.0.3.tgz", + "integrity": "sha512-Fd4gABb+ycGAmKou8eMftCupSir5lRxqf4aD/vd0cD2qc4HL07OjCeuHMr8Ro4CoMaeCKDB0/ECBOVWjTwUvPQ==", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=8" + } + }, "node_modules/is-plain-obj": { "version": "2.1.0", "resolved": "https://registry.npmjs.org/is-plain-obj/-/is-plain-obj-2.1.0.tgz", @@ -3044,10 +3043,11 @@ "license": "MIT" }, "node_modules/js-yaml": { - "version": "3.14.1", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-3.14.1.tgz", - "integrity": "sha512-okMH7OXXJ7YrN9Ok3/SXrnu4iX9yOk+25nqX4imS2npuvTYDmo/QEZoqwZkYaIDk3jVvBOTOIEgEhaLOynBS9g==", + "version": "3.14.2", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-3.14.2.tgz", + "integrity": "sha512-PMSmkqxr106Xa156c2M265Z+FTrPl+oxd/rgOQy2tijQeK5TxQ43psO1ZCwhVOSdnn+RzkzlRz/eY4BgJBYVpg==", "dev": true, + "license": "MIT", "dependencies": { "argparse": "^1.0.7", "esprima": "^4.0.0" @@ -3089,10 +3089,11 @@ } }, "node_modules/jshint": { - "version": "2.13.4", - "resolved": "https://registry.npmjs.org/jshint/-/jshint-2.13.4.tgz", - "integrity": "sha512-HO3bosL84b2qWqI0q+kpT/OpRJwo0R4ivgmxaO848+bo10rc50SkPnrtwSFXttW0ym4np8jbJvLwk5NziB7jIw==", + "version": "2.13.6", + "resolved": "https://registry.npmjs.org/jshint/-/jshint-2.13.6.tgz", + "integrity": "sha512-IVdB4G0NTTeQZrBoM8C5JFVLjV2KtZ9APgybDA1MK73xb09qFs0jCXyQLnCOp1cSZZZbvhq/6mfXHUTaDkffuQ==", "dev": true, + "license": "MIT", "dependencies": { "cli": "~1.0.0", "console-browserify": "1.1.x", @@ -3419,9 +3420,10 @@ } }, "node_modules/lodash": { - "version": "4.17.21", - "resolved": "https://registry.npmjs.org/lodash/-/lodash-4.17.21.tgz", - "integrity": "sha512-v2kDEe57lecTulaDIuNTPy3Ry4gLGJ6Z1O3vE1krgXZNrsQ+LFTGHVxVjcXPs17LhbZVGedAJv8XZ1tvj5FvSg==" + "version": "4.17.23", + "resolved": "https://registry.npmjs.org/lodash/-/lodash-4.17.23.tgz", + "integrity": "sha512-LgVTMpQtIopCi79SJeDiP0TfWi5CNEc/L/aRdTh3yIvmZXTnheWpKjSZhnvMl8iXbC1tFg9gdHHDMLoV7CnG+w==", + "license": "MIT" }, "node_modules/lodash.flattendeep": { "version": "4.4.0", @@ -3543,10 +3545,11 @@ } }, "node_modules/minimatch": { - "version": "3.1.2", - "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-3.1.2.tgz", - "integrity": "sha512-J7p63hRiAjw1NDEww1W7i37+ByIrOWO5XQQAzZ3VOcL0PNybwpfmV/N05zFAzwQ9USyEcX6t3UO+K5aqBQOIHw==", + "version": "3.1.5", + "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-3.1.5.tgz", + "integrity": "sha512-VgjWUsnnT6n+NUk6eZq77zeFdpW2LWDzP6zFGrCbHXiYNul5Dzqk2HHQ5uFH2DNW5Xbp8+jVzaeNt94ssEEl4w==", "dev": true, + "license": "ISC", "dependencies": { "brace-expansion": "^1.1.7" }, @@ -3658,9 +3661,9 @@ } }, "node_modules/minizlib": { - "version": "3.0.2", - "resolved": "https://registry.npmjs.org/minizlib/-/minizlib-3.0.2.tgz", - "integrity": "sha512-oG62iEk+CYt5Xj2YqI5Xi9xWUeZhDI8jjQmC5oThVH5JGCTgIjr7ciJDzC7MBzYd//WvR1OTmP5Q38Q8ShQtVA==", + "version": "3.1.0", + "resolved": "https://registry.npmjs.org/minizlib/-/minizlib-3.1.0.tgz", + "integrity": "sha512-KZxYo1BUkWD2TVFLr0MQoM8vUUigWD3LlD83a/75BqC+4qE0Hb1Vo5v1FgcfaNXvfXzr+5EhQ6ing/CaBijTlw==", "license": "MIT", "dependencies": { "minipass": "^7.1.2" @@ -3691,9 +3694,9 @@ } }, "node_modules/mocha": { - "version": "11.4.0", - "resolved": "https://registry.npmjs.org/mocha/-/mocha-11.4.0.tgz", - "integrity": "sha512-O6oi5Y9G6uu8f9iqXR6iKNLWHLRex3PKbmHynfpmUnMJJGrdgXh8ZmS85Ei5KR2Gnl+/gQ9s+Ktv5CqKybNw4A==", + "version": "11.7.5", + "resolved": "https://registry.npmjs.org/mocha/-/mocha-11.7.5.tgz", + "integrity": "sha512-mTT6RgopEYABzXWFx+GcJ+ZQ32kp4fMf0xvpZIIfSq9Z8lC/++MtcCnQ9t5FP2veYEP95FIYSvW+U9fV4xrlig==", "dev": true, "license": "MIT", "dependencies": { @@ -3705,15 +3708,16 @@ "find-up": "^5.0.0", "glob": "^10.4.5", "he": "^1.2.0", + "is-path-inside": "^3.0.3", "js-yaml": "^4.1.0", "log-symbols": "^4.1.0", - "minimatch": "^5.1.6", + "minimatch": "^9.0.5", "ms": "^2.1.3", "picocolors": "^1.1.1", "serialize-javascript": "^6.0.2", "strip-json-comments": "^3.1.1", "supports-color": "^8.1.1", - "workerpool": "^6.5.1", + "workerpool": "^9.2.0", "yargs": "^17.7.2", "yargs-parser": "^21.1.1", "yargs-unparser": "^2.0.0" @@ -3734,9 +3738,9 @@ "license": "Python-2.0" }, "node_modules/mocha/node_modules/brace-expansion": { - "version": "2.0.1", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.0.1.tgz", - "integrity": "sha512-XnAIvQ8eM+kC6aULx6wuQiwVsnzsi9d3WxzV3FpWTGA19F621kwdbsAcFKXgKUHZWsy+mY6iL1sHTxWEFCytDA==", + "version": "2.0.2", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.0.2.tgz", + "integrity": "sha512-Jt0vHyM+jmUBqojB7E1NIYadt0vI0Qxjxd2TErW94wDz+E2LAm5vKMXXwg6ZZBTHPuUlDgQHKXvjGBdfcF1ZDQ==", "dev": true, "license": "MIT", "dependencies": { @@ -3776,9 +3780,10 @@ } }, "node_modules/mocha/node_modules/glob": { - "version": "10.4.5", - "resolved": "https://registry.npmjs.org/glob/-/glob-10.4.5.tgz", - "integrity": "sha512-7Bv8RF0k6xjo7d4A/PxYLbUCfb6c+Vpd2/mB2yRDlew7Jb5hEXiCD9ibfO7wpk8i4sevK6DFny9h7EYbM3/sHg==", + "version": "10.5.0", + "resolved": "https://registry.npmjs.org/glob/-/glob-10.5.0.tgz", + "integrity": "sha512-DfXN8DfhJ7NH3Oe7cFmu3NCu1wKbkReJ8TorzSAFbSKrlNaQSKfIzqYqVY8zlbs2NLBbWpRiU52GX2PbaBVNkg==", + "deprecated": "Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting i@izs.me", "dev": true, "license": "ISC", "dependencies": { @@ -3796,26 +3801,10 @@ "url": "https://github.com/sponsors/isaacs" } }, - "node_modules/mocha/node_modules/glob/node_modules/minimatch": { - "version": "9.0.5", - "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-9.0.5.tgz", - "integrity": "sha512-G6T0ZX48xgozx7587koeX9Ys2NYy6Gmv//P89sEte9V9whIapMNF4idKxnW2QtCcLiTWlb/wfCabAtAFWhhBow==", - "dev": true, - "license": "ISC", - "dependencies": { - "brace-expansion": "^2.0.1" - }, - "engines": { - "node": ">=16 || 14 >=14.17" - }, - "funding": { - "url": "https://github.com/sponsors/isaacs" - } - }, "node_modules/mocha/node_modules/js-yaml": { - "version": "4.1.0", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.1.0.tgz", - "integrity": "sha512-wpxZs9NoxZaJESJGIZTyDEaYpl0FKSA+FB9aJiyemKhMwkxQg63h4T1KJgUGHpTqPDNRcmmYLugrRjJlBtWvRA==", + "version": "4.1.1", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.1.1.tgz", + "integrity": "sha512-qQKT4zQxXl8lLwBtHMWwaTcGfFOZviOJet3Oy/xmGk2gZH677CJM9EvtfdSkgWcATZhj/55JZ0rmy3myCT5lsA==", "dev": true, "license": "MIT", "dependencies": { @@ -3842,16 +3831,19 @@ } }, "node_modules/mocha/node_modules/minimatch": { - "version": "5.1.6", - "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-5.1.6.tgz", - "integrity": "sha512-lKwV/1brpG6mBUFHtb7NUmtABCb2WZZmm2wNiOA5hAb8VdCS4B3dtMWyvcoViccwAW/COERjXLt0zP1zXUN26g==", + "version": "9.0.9", + "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-9.0.9.tgz", + "integrity": "sha512-OBwBN9AL4dqmETlpS2zasx+vTeWclWzkblfZk7KTA5j3jeOONz/tRCnZomUyvNg83wL5Zv9Ss6HMJXAgL8R2Yg==", "dev": true, "license": "ISC", "dependencies": { - "brace-expansion": "^2.0.1" + "brace-expansion": "^2.0.2" }, "engines": { - "node": ">=10" + "node": ">=16 || 14 >=14.17" + }, + "funding": { + "url": "https://github.com/sponsors/isaacs" } }, "node_modules/mocha/node_modules/minipass": { @@ -4515,7 +4507,6 @@ "resolved": "https://registry.npmjs.org/picomatch/-/picomatch-4.0.2.tgz", "integrity": "sha512-M7BAV6Rlcy5u+m6oPhAPFgJTzAioX/6B0DxyvDlo9l8+T3nLKbrczg2WLUyzd45L8RqfUMyGPzekbMvX2Ldkwg==", "license": "MIT", - "peer": true, "engines": { "node": ">=12" }, @@ -4865,12 +4856,6 @@ "url": "https://github.com/sponsors/ljharb" } }, - "node_modules/safer-buffer": { - "version": "2.1.2", - "resolved": "https://registry.npmjs.org/safer-buffer/-/safer-buffer-2.1.2.tgz", - "integrity": "sha512-YZo3K82SD7Riyi0E1EQPojLz7kpepnSQI9IyPbHHg1XXXevb5dJI7tpyN2ADxGcQbHG7vcyRHk0cbwqcQriUtg==", - "optional": true - }, "node_modules/sax": { "version": "1.2.1", "resolved": "https://registry.npmjs.org/sax/-/sax-1.2.1.tgz", @@ -5172,16 +5157,15 @@ } }, "node_modules/tar": { - "version": "7.4.3", - "resolved": "https://registry.npmjs.org/tar/-/tar-7.4.3.tgz", - "integrity": "sha512-5S7Va8hKfV7W5U6g3aYxXmlPoZVAwUMy9AOKyF2fVuZa2UD3qZjg578OrLRt8PcNN1PleVaL/5/yYATNL0ICUw==", - "license": "ISC", + "version": "7.5.10", + "resolved": "https://registry.npmjs.org/tar/-/tar-7.5.10.tgz", + "integrity": "sha512-8mOPs1//5q/rlkNSPcCegA6hiHJYDmSLEI8aMH/CdSQJNWztHC9WHNam5zdQlfpTwB9Xp7IBEsHfV5LKMJGVAw==", + "license": "BlueOak-1.0.0", "dependencies": { "@isaacs/fs-minipass": "^4.0.0", "chownr": "^3.0.0", "minipass": "^7.1.2", - "minizlib": "^3.0.1", - "mkdirp": "^3.0.1", + "minizlib": "^3.1.0", "yallist": "^5.0.0" }, "engines": { @@ -5221,21 +5205,6 @@ "node": ">=16 || 14 >=14.17" } }, - "node_modules/tar/node_modules/mkdirp": { - "version": "3.0.1", - "resolved": "https://registry.npmjs.org/mkdirp/-/mkdirp-3.0.1.tgz", - "integrity": "sha512-+NsyUUAZDmo6YVHzL/stxSu3t9YS1iljliy3BSDrXJ/dkn1KYdmtZODGGjLcc9XLgVVpH4KshHB8XmZgMhaBXg==", - "license": "MIT", - "bin": { - "mkdirp": "dist/cjs/src/bin.js" - }, - "engines": { - "node": ">=10" - }, - "funding": { - "url": "https://github.com/sponsors/isaacs" - } - }, "node_modules/tar/node_modules/yallist": { "version": "5.0.0", "resolved": "https://registry.npmjs.org/yallist/-/yallist-5.0.0.tgz", @@ -5726,9 +5695,9 @@ } }, "node_modules/workerpool": { - "version": "6.5.1", - "resolved": "https://registry.npmjs.org/workerpool/-/workerpool-6.5.1.tgz", - "integrity": "sha512-Fs4dNYcsdpYSAfVxhnl1L5zTksjvOJxtC5hzMNl+1t9B8hTJTdKDyZ5ju7ztgPy+ft9tBFXoOlDNiOT9WUXZlA==", + "version": "9.3.4", + "resolved": "https://registry.npmjs.org/workerpool/-/workerpool-9.3.4.tgz", + "integrity": "sha512-TmPRQYYSAnnDiEB0P/Ytip7bFGvqnSU6I2BcuSw7Hx+JSg/DsUi5ebYfc8GYaSdpuvOcEs6dXxPurOYpe9QFwg==", "dev": true, "license": "Apache-2.0" }, @@ -5984,7 +5953,6 @@ "resolved": "https://registry.npmjs.org/@babel/core/-/core-7.26.7.tgz", "integrity": "sha512-SRijHmF0PSPgLIBYlWnG0hyeJLwXE2CgpsXaMOrtt2yp9/86ALw6oUlj9KYuZ0JN07T4eBMVIW4li/9S1j2BGA==", "dev": true, - "peer": true, "requires": { "@ampproject/remapping": "^2.2.0", "@babel/code-frame": "^7.26.2", @@ -6439,9 +6407,9 @@ } }, "aws-sdk": { - "version": "2.1692.0", - "resolved": "https://registry.npmjs.org/aws-sdk/-/aws-sdk-2.1692.0.tgz", - "integrity": "sha512-x511uiJ/57FIsbgUe5csJ13k3uzu25uWQE+XqfBis/sB0SFoiElJWXRkgEAUh0U6n40eT3ay5Ue4oPkRMu1LYw==", + "version": "2.1693.0", + "resolved": "https://registry.npmjs.org/aws-sdk/-/aws-sdk-2.1693.0.tgz", + "integrity": "sha512-cJmb8xEnVLT+R6fBS5sn/EFJiX7tUnDaPtOPZ1vFbOJtd0fnZn/Ky2XGgsvvoeliWeH7mL3TWSX5zXXGSQV6gQ==", "dev": true, "requires": { "buffer": "4.9.2", @@ -6514,9 +6482,9 @@ "dev": true }, "brace-expansion": { - "version": "1.1.11", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.11.tgz", - "integrity": "sha512-iCuPHDFgrHX7H2vEI/5xpz07zSHB00TpugqhmYtVmMO6518mCuRMoOYFldEBl0g187ufozdaHgWKcYFb61qGiA==", + "version": "1.1.12", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.12.tgz", + "integrity": "sha512-9T9UjW3r0UW5c1Q7GTwllptXwhvYmEzFhzMfZ9H7FQWt+uZePjZPjBP/W1ZEyZ1twGWom5/56TF4lPcqjnDHcg==", "dev": true, "requires": { "balanced-match": "^1.0.0", @@ -6534,7 +6502,6 @@ "resolved": "https://registry.npmjs.org/browserslist/-/browserslist-4.24.4.tgz", "integrity": "sha512-KDi1Ny1gSePi1vm0q4oxSF8b4DR44GF4BbmS2YdhPLOEqd8pDviZOGH/GsmRwoWJ2+5Lr085X7naowMwKHDG1A==", "dev": true, - "peer": true, "requires": { "caniuse-lite": "^1.0.30001688", "electron-to-chromium": "^1.5.73", @@ -6579,9 +6546,9 @@ }, "dependencies": { "brace-expansion": { - "version": "2.0.1", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.0.1.tgz", - "integrity": "sha512-XnAIvQ8eM+kC6aULx6wuQiwVsnzsi9d3WxzV3FpWTGA19F621kwdbsAcFKXgKUHZWsy+mY6iL1sHTxWEFCytDA==", + "version": "2.0.2", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.0.2.tgz", + "integrity": "sha512-Jt0vHyM+jmUBqojB7E1NIYadt0vI0Qxjxd2TErW94wDz+E2LAm5vKMXXwg6ZZBTHPuUlDgQHKXvjGBdfcF1ZDQ==", "requires": { "balanced-match": "^1.0.0" } @@ -6595,9 +6562,9 @@ } }, "glob": { - "version": "10.4.5", - "resolved": "https://registry.npmjs.org/glob/-/glob-10.4.5.tgz", - "integrity": "sha512-7Bv8RF0k6xjo7d4A/PxYLbUCfb6c+Vpd2/mB2yRDlew7Jb5hEXiCD9ibfO7wpk8i4sevK6DFny9h7EYbM3/sHg==", + "version": "10.5.0", + "resolved": "https://registry.npmjs.org/glob/-/glob-10.5.0.tgz", + "integrity": "sha512-DfXN8DfhJ7NH3Oe7cFmu3NCu1wKbkReJ8TorzSAFbSKrlNaQSKfIzqYqVY8zlbs2NLBbWpRiU52GX2PbaBVNkg==", "requires": { "foreground-child": "^3.1.0", "jackspeak": "^3.1.2", @@ -6608,11 +6575,11 @@ } }, "minimatch": { - "version": "9.0.5", - "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-9.0.5.tgz", - "integrity": "sha512-G6T0ZX48xgozx7587koeX9Ys2NYy6Gmv//P89sEte9V9whIapMNF4idKxnW2QtCcLiTWlb/wfCabAtAFWhhBow==", + "version": "9.0.9", + "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-9.0.9.tgz", + "integrity": "sha512-OBwBN9AL4dqmETlpS2zasx+vTeWclWzkblfZk7KTA5j3jeOONz/tRCnZomUyvNg83wL5Zv9Ss6HMJXAgL8R2Yg==", "requires": { - "brace-expansion": "^2.0.1" + "brace-expansion": "^2.0.2" } }, "minipass": { @@ -7706,14 +7673,6 @@ "debug": "4" } }, - "iconv-lite": { - "version": "https://registry.npmjs.org/iconv-lite/-/iconv-lite-0.6.3.tgz", - "integrity": "sha512-4fCk79wshMdzMp2rH06qWrJE4iolqLhCUH+OiuIgU++RB0+94NlDL81atO7GX55uUKueo0txHNtvEyI6D7WdMw==", - "optional": true, - "requires": { - "safer-buffer": ">= 2.1.2 < 3.0.0" - } - }, "ieee754": { "version": "1.1.13", "resolved": "https://registry.npmjs.org/ieee754/-/ieee754-1.1.13.tgz", @@ -7845,6 +7804,12 @@ "integrity": "sha1-aRC8pdqMleeEtXUbl2z1oQ/uNtI=", "dev": true }, + "is-path-inside": { + "version": "3.0.3", + "resolved": "https://registry.npmjs.org/is-path-inside/-/is-path-inside-3.0.3.tgz", + "integrity": "sha512-Fd4gABb+ycGAmKou8eMftCupSir5lRxqf4aD/vd0cD2qc4HL07OjCeuHMr8Ro4CoMaeCKDB0/ECBOVWjTwUvPQ==", + "dev": true + }, "is-plain-obj": { "version": "2.1.0", "resolved": "https://registry.npmjs.org/is-plain-obj/-/is-plain-obj-2.1.0.tgz", @@ -8100,9 +8065,9 @@ "dev": true }, "js-yaml": { - "version": "3.14.1", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-3.14.1.tgz", - "integrity": "sha512-okMH7OXXJ7YrN9Ok3/SXrnu4iX9yOk+25nqX4imS2npuvTYDmo/QEZoqwZkYaIDk3jVvBOTOIEgEhaLOynBS9g==", + "version": "3.14.2", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-3.14.2.tgz", + "integrity": "sha512-PMSmkqxr106Xa156c2M265Z+FTrPl+oxd/rgOQy2tijQeK5TxQ43psO1ZCwhVOSdnn+RzkzlRz/eY4BgJBYVpg==", "dev": true, "requires": { "argparse": "^1.0.7", @@ -8129,9 +8094,9 @@ "dev": true }, "jshint": { - "version": "2.13.4", - "resolved": "https://registry.npmjs.org/jshint/-/jshint-2.13.4.tgz", - "integrity": "sha512-HO3bosL84b2qWqI0q+kpT/OpRJwo0R4ivgmxaO848+bo10rc50SkPnrtwSFXttW0ym4np8jbJvLwk5NziB7jIw==", + "version": "2.13.6", + "resolved": "https://registry.npmjs.org/jshint/-/jshint-2.13.6.tgz", + "integrity": "sha512-IVdB4G0NTTeQZrBoM8C5JFVLjV2KtZ9APgybDA1MK73xb09qFs0jCXyQLnCOp1cSZZZbvhq/6mfXHUTaDkffuQ==", "dev": true, "requires": { "cli": "~1.0.0", @@ -8413,9 +8378,9 @@ } }, "lodash": { - "version": "4.17.21", - "resolved": "https://registry.npmjs.org/lodash/-/lodash-4.17.21.tgz", - "integrity": "sha512-v2kDEe57lecTulaDIuNTPy3Ry4gLGJ6Z1O3vE1krgXZNrsQ+LFTGHVxVjcXPs17LhbZVGedAJv8XZ1tvj5FvSg==" + "version": "4.17.23", + "resolved": "https://registry.npmjs.org/lodash/-/lodash-4.17.23.tgz", + "integrity": "sha512-LgVTMpQtIopCi79SJeDiP0TfWi5CNEc/L/aRdTh3yIvmZXTnheWpKjSZhnvMl8iXbC1tFg9gdHHDMLoV7CnG+w==" }, "lodash.flattendeep": { "version": "4.4.0", @@ -8497,9 +8462,9 @@ "integrity": "sha512-z0yWI+4FDrrweS8Zmt4Ej5HdJmky15+L2e6Wgn3+iK5fWzb6T3fhNFq2+MeTRb064c6Wr4N/wv0DzQTjNzHNGQ==" }, "minimatch": { - "version": "3.1.2", - "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-3.1.2.tgz", - "integrity": "sha512-J7p63hRiAjw1NDEww1W7i37+ByIrOWO5XQQAzZ3VOcL0PNybwpfmV/N05zFAzwQ9USyEcX6t3UO+K5aqBQOIHw==", + "version": "3.1.5", + "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-3.1.5.tgz", + "integrity": "sha512-VgjWUsnnT6n+NUk6eZq77zeFdpW2LWDzP6zFGrCbHXiYNul5Dzqk2HHQ5uFH2DNW5Xbp8+jVzaeNt94ssEEl4w==", "dev": true, "requires": { "brace-expansion": "^1.1.7" @@ -8577,9 +8542,9 @@ } }, "minizlib": { - "version": "3.0.2", - "resolved": "https://registry.npmjs.org/minizlib/-/minizlib-3.0.2.tgz", - "integrity": "sha512-oG62iEk+CYt5Xj2YqI5Xi9xWUeZhDI8jjQmC5oThVH5JGCTgIjr7ciJDzC7MBzYd//WvR1OTmP5Q38Q8ShQtVA==", + "version": "3.1.0", + "resolved": "https://registry.npmjs.org/minizlib/-/minizlib-3.1.0.tgz", + "integrity": "sha512-KZxYo1BUkWD2TVFLr0MQoM8vUUigWD3LlD83a/75BqC+4qE0Hb1Vo5v1FgcfaNXvfXzr+5EhQ6ing/CaBijTlw==", "requires": { "minipass": "^7.1.2" }, @@ -8601,9 +8566,9 @@ } }, "mocha": { - "version": "11.4.0", - "resolved": "https://registry.npmjs.org/mocha/-/mocha-11.4.0.tgz", - "integrity": "sha512-O6oi5Y9G6uu8f9iqXR6iKNLWHLRex3PKbmHynfpmUnMJJGrdgXh8ZmS85Ei5KR2Gnl+/gQ9s+Ktv5CqKybNw4A==", + "version": "11.7.5", + "resolved": "https://registry.npmjs.org/mocha/-/mocha-11.7.5.tgz", + "integrity": "sha512-mTT6RgopEYABzXWFx+GcJ+ZQ32kp4fMf0xvpZIIfSq9Z8lC/++MtcCnQ9t5FP2veYEP95FIYSvW+U9fV4xrlig==", "dev": true, "requires": { "browser-stdout": "^1.3.1", @@ -8614,15 +8579,16 @@ "find-up": "^5.0.0", "glob": "^10.4.5", "he": "^1.2.0", + "is-path-inside": "^3.0.3", "js-yaml": "^4.1.0", "log-symbols": "^4.1.0", - "minimatch": "^5.1.6", + "minimatch": "^9.0.5", "ms": "^2.1.3", "picocolors": "^1.1.1", "serialize-javascript": "^6.0.2", "strip-json-comments": "^3.1.1", "supports-color": "^8.1.1", - "workerpool": "^6.5.1", + "workerpool": "^9.2.0", "yargs": "^17.7.2", "yargs-parser": "^21.1.1", "yargs-unparser": "^2.0.0" @@ -8635,9 +8601,9 @@ "dev": true }, "brace-expansion": { - "version": "2.0.1", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.0.1.tgz", - "integrity": "sha512-XnAIvQ8eM+kC6aULx6wuQiwVsnzsi9d3WxzV3FpWTGA19F621kwdbsAcFKXgKUHZWsy+mY6iL1sHTxWEFCytDA==", + "version": "2.0.2", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.0.2.tgz", + "integrity": "sha512-Jt0vHyM+jmUBqojB7E1NIYadt0vI0Qxjxd2TErW94wDz+E2LAm5vKMXXwg6ZZBTHPuUlDgQHKXvjGBdfcF1ZDQ==", "dev": true, "requires": { "balanced-match": "^1.0.0" @@ -8665,9 +8631,9 @@ } }, "glob": { - "version": "10.4.5", - "resolved": "https://registry.npmjs.org/glob/-/glob-10.4.5.tgz", - "integrity": "sha512-7Bv8RF0k6xjo7d4A/PxYLbUCfb6c+Vpd2/mB2yRDlew7Jb5hEXiCD9ibfO7wpk8i4sevK6DFny9h7EYbM3/sHg==", + "version": "10.5.0", + "resolved": "https://registry.npmjs.org/glob/-/glob-10.5.0.tgz", + "integrity": "sha512-DfXN8DfhJ7NH3Oe7cFmu3NCu1wKbkReJ8TorzSAFbSKrlNaQSKfIzqYqVY8zlbs2NLBbWpRiU52GX2PbaBVNkg==", "dev": true, "requires": { "foreground-child": "^3.1.0", @@ -8676,23 +8642,12 @@ "minipass": "^7.1.2", "package-json-from-dist": "^1.0.0", "path-scurry": "^1.11.1" - }, - "dependencies": { - "minimatch": { - "version": "9.0.5", - "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-9.0.5.tgz", - "integrity": "sha512-G6T0ZX48xgozx7587koeX9Ys2NYy6Gmv//P89sEte9V9whIapMNF4idKxnW2QtCcLiTWlb/wfCabAtAFWhhBow==", - "dev": true, - "requires": { - "brace-expansion": "^2.0.1" - } - } } }, "js-yaml": { - "version": "4.1.0", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.1.0.tgz", - "integrity": "sha512-wpxZs9NoxZaJESJGIZTyDEaYpl0FKSA+FB9aJiyemKhMwkxQg63h4T1KJgUGHpTqPDNRcmmYLugrRjJlBtWvRA==", + "version": "4.1.1", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.1.1.tgz", + "integrity": "sha512-qQKT4zQxXl8lLwBtHMWwaTcGfFOZviOJet3Oy/xmGk2gZH677CJM9EvtfdSkgWcATZhj/55JZ0rmy3myCT5lsA==", "dev": true, "requires": { "argparse": "^2.0.1" @@ -8708,12 +8663,12 @@ } }, "minimatch": { - "version": "5.1.6", - "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-5.1.6.tgz", - "integrity": "sha512-lKwV/1brpG6mBUFHtb7NUmtABCb2WZZmm2wNiOA5hAb8VdCS4B3dtMWyvcoViccwAW/COERjXLt0zP1zXUN26g==", + "version": "9.0.9", + "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-9.0.9.tgz", + "integrity": "sha512-OBwBN9AL4dqmETlpS2zasx+vTeWclWzkblfZk7KTA5j3jeOONz/tRCnZomUyvNg83wL5Zv9Ss6HMJXAgL8R2Yg==", "dev": true, "requires": { - "brace-expansion": "^2.0.1" + "brace-expansion": "^2.0.2" } }, "minipass": { @@ -9183,8 +9138,7 @@ "picomatch": { "version": "4.0.2", "resolved": "https://registry.npmjs.org/picomatch/-/picomatch-4.0.2.tgz", - "integrity": "sha512-M7BAV6Rlcy5u+m6oPhAPFgJTzAioX/6B0DxyvDlo9l8+T3nLKbrczg2WLUyzd45L8RqfUMyGPzekbMvX2Ldkwg==", - "peer": true + "integrity": "sha512-M7BAV6Rlcy5u+m6oPhAPFgJTzAioX/6B0DxyvDlo9l8+T3nLKbrczg2WLUyzd45L8RqfUMyGPzekbMvX2Ldkwg==" }, "pkg-dir": { "version": "4.2.0", @@ -9423,12 +9377,6 @@ "is-regex": "^1.2.1" } }, - "safer-buffer": { - "version": "2.1.2", - "resolved": "https://registry.npmjs.org/safer-buffer/-/safer-buffer-2.1.2.tgz", - "integrity": "sha512-YZo3K82SD7Riyi0E1EQPojLz7kpepnSQI9IyPbHHg1XXXevb5dJI7tpyN2ADxGcQbHG7vcyRHk0cbwqcQriUtg==", - "optional": true - }, "sax": { "version": "1.2.1", "resolved": "https://registry.npmjs.org/sax/-/sax-1.2.1.tgz", @@ -9642,15 +9590,14 @@ } }, "tar": { - "version": "7.4.3", - "resolved": "https://registry.npmjs.org/tar/-/tar-7.4.3.tgz", - "integrity": "sha512-5S7Va8hKfV7W5U6g3aYxXmlPoZVAwUMy9AOKyF2fVuZa2UD3qZjg578OrLRt8PcNN1PleVaL/5/yYATNL0ICUw==", + "version": "7.5.10", + "resolved": "https://registry.npmjs.org/tar/-/tar-7.5.10.tgz", + "integrity": "sha512-8mOPs1//5q/rlkNSPcCegA6hiHJYDmSLEI8aMH/CdSQJNWztHC9WHNam5zdQlfpTwB9Xp7IBEsHfV5LKMJGVAw==", "requires": { "@isaacs/fs-minipass": "^4.0.0", "chownr": "^3.0.0", "minipass": "^7.1.2", - "minizlib": "^3.0.1", - "mkdirp": "^3.0.1", + "minizlib": "^3.1.0", "yallist": "^5.0.0" }, "dependencies": { @@ -9659,11 +9606,6 @@ "resolved": "https://registry.npmjs.org/minipass/-/minipass-7.1.2.tgz", "integrity": "sha512-qOOzS1cBTWYF4BH8fVePDBOO9iptMnGUEZwNc/cMWnTV2nVLZ7VoNWEPHkYczZA0pdoA7dl6e7FL659nX9S2aw==" }, - "mkdirp": { - "version": "3.0.1", - "resolved": "https://registry.npmjs.org/mkdirp/-/mkdirp-3.0.1.tgz", - "integrity": "sha512-+NsyUUAZDmo6YVHzL/stxSu3t9YS1iljliy3BSDrXJ/dkn1KYdmtZODGGjLcc9XLgVVpH4KshHB8XmZgMhaBXg==" - }, "yallist": { "version": "5.0.0", "resolved": "https://registry.npmjs.org/yallist/-/yallist-5.0.0.tgz", @@ -10075,9 +10017,9 @@ "dev": true }, "workerpool": { - "version": "6.5.1", - "resolved": "https://registry.npmjs.org/workerpool/-/workerpool-6.5.1.tgz", - "integrity": "sha512-Fs4dNYcsdpYSAfVxhnl1L5zTksjvOJxtC5hzMNl+1t9B8hTJTdKDyZ5ju7ztgPy+ft9tBFXoOlDNiOT9WUXZlA==", + "version": "9.3.4", + "resolved": "https://registry.npmjs.org/workerpool/-/workerpool-9.3.4.tgz", + "integrity": "sha512-TmPRQYYSAnnDiEB0P/Ytip7bFGvqnSU6I2BcuSw7Hx+JSg/DsUi5ebYfc8GYaSdpuvOcEs6dXxPurOYpe9QFwg==", "dev": true }, "wrap-ansi": { From 65e36eeb7b3b3edcb7c19aa10d619ada3b76bca6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Alex=20Aveill=C3=A1n?= Date: Fri, 6 Mar 2026 14:06:57 +0100 Subject: [PATCH 2/9] fix: add npm overrides to resolve remaining high-severity vulnerabilities Adds overrides in package.json for transitive dependencies that cannot be updated within their parent packages declared semver ranges: - mocha > diff: ^7.0.0 overridden to ^8.0.3 Fixes DoS in parsePatch/applyPatch (GHSA-73rr-hh4g-fpgx) - mocha > serialize-javascript: ^6.0.2 overridden to ^7.0.4 Fixes RCE via RegExp.flags and Date.prototype.toISOString (GHSA-5c6j-r48x-rmvq) - jshint > minimatch: ~3.0.2 overridden to 3.1.5 Fixes multiple ReDoS vulnerabilities (GHSA-3ppc-4f35-3m26, GHSA-7r86-cg39-jmmj, GHSA-23c5-xmqv-rm74) Remaining: aws-sdk v2 low-severity advisory (GHSA-j965-2qgj-vjmq) affects all of v2, requires migration to v3 which is out of scope. Lint (jshint) verified passing after minimatch override. --- package-lock.json | 70 ++++++++++++++++------------------------------- package.json | 9 ++++++ 2 files changed, 32 insertions(+), 47 deletions(-) diff --git a/package-lock.json b/package-lock.json index 9188bb409..7f1879762 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1672,9 +1672,9 @@ } }, "node_modules/diff": { - "version": "7.0.0", - "resolved": "https://registry.npmjs.org/diff/-/diff-7.0.0.tgz", - "integrity": "sha512-PJWHUb1RFevKCwaFA9RlG5tCd+FO5iRh9A8HEtkmBH2Li03iJriB6m6JIN4rGz3K3JLawI7/veA1xzRKP6ISBw==", + "version": "8.0.3", + "resolved": "https://registry.npmjs.org/diff/-/diff-8.0.3.tgz", + "integrity": "sha512-qejHi7bcSD4hQAZE0tNAawRK1ZtafHDmMTMkrrIGgSLl7hTnQHmKCeB45xAcbfTqK2zowkM3j3bHt/4b/ARbYQ==", "dev": true, "license": "BSD-3-Clause", "engines": { @@ -3100,7 +3100,7 @@ "exit": "0.1.x", "htmlparser2": "3.8.x", "lodash": "~4.17.21", - "minimatch": "~3.0.2", + "minimatch": "3.1.5", "strip-json-comments": "1.0.x" }, "bin": { @@ -3189,9 +3189,8 @@ "dev": true }, "node_modules/jshint/node_modules/minimatch": { - "version": "3.0.8", - "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-3.0.8.tgz", - "integrity": "sha512-6FsRAQsxQ61mw+qP1ZzbL9Bc78x2p5OqNgNpnoAFLTrX8n5Kxph0CsnhmKKNXTWjXqU5L0pGPR7hYk+XWZr60Q==", + "version": "3.1.5", + "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-3.1.5.tgz", "dev": true, "dependencies": { "brace-expansion": "^1.1.7" @@ -4636,16 +4635,6 @@ "url": "https://github.com/sponsors/sindresorhus" } }, - "node_modules/randombytes": { - "version": "2.1.0", - "resolved": "https://registry.npmjs.org/randombytes/-/randombytes-2.1.0.tgz", - "integrity": "sha512-vYl3iOX+4CKUWuxGi9Ukhie6fsqXqS9FE2Zaic4tNFD2N2QQaXOMFbuKK4QmDHC0JO6B1Zp41J0LpT0oR68amQ==", - "dev": true, - "license": "MIT", - "dependencies": { - "safe-buffer": "^5.1.0" - } - }, "node_modules/readdirp": { "version": "4.1.2", "resolved": "https://registry.npmjs.org/readdirp/-/readdirp-4.1.2.tgz", @@ -4876,13 +4865,13 @@ } }, "node_modules/serialize-javascript": { - "version": "6.0.2", - "resolved": "https://registry.npmjs.org/serialize-javascript/-/serialize-javascript-6.0.2.tgz", - "integrity": "sha512-Saa1xPByTTq2gdeFZYLLo+RFE35NHZkAbqZeWNd3BpzppeVisAqpDjcp8dyf6uIvEqJRd46jemmyA4iFIeVk8g==", + "version": "7.0.4", + "resolved": "https://registry.npmjs.org/serialize-javascript/-/serialize-javascript-7.0.4.tgz", + "integrity": "sha512-DuGdB+Po43Q5Jxwpzt1lhyFSYKryqoNjQSA9M92tyw0lyHIOur+XCalOUe0KTJpyqzT8+fQ5A0Jf7vCx/NKmIg==", "dev": true, "license": "BSD-3-Clause", - "dependencies": { - "randombytes": "^2.1.0" + "engines": { + "node": ">=20.0.0" } }, "node_modules/set-blocking": { @@ -7079,9 +7068,9 @@ "integrity": "sha512-3UDv+G9CsCKO1WKMGw9fwq/SWJYbI0c5Y7LU1AXYoDdbhE2AHQ6N6Nb34sG8Fj7T5APy8qXDCKuuIHd1BR0tVA==" }, "diff": { - "version": "7.0.0", - "resolved": "https://registry.npmjs.org/diff/-/diff-7.0.0.tgz", - "integrity": "sha512-PJWHUb1RFevKCwaFA9RlG5tCd+FO5iRh9A8HEtkmBH2Li03iJriB6m6JIN4rGz3K3JLawI7/veA1xzRKP6ISBw==", + "version": "8.0.3", + "resolved": "https://registry.npmjs.org/diff/-/diff-8.0.3.tgz", + "integrity": "sha512-qejHi7bcSD4hQAZE0tNAawRK1ZtafHDmMTMkrrIGgSLl7hTnQHmKCeB45xAcbfTqK2zowkM3j3bHt/4b/ARbYQ==", "dev": true }, "dunder-proto": { @@ -8104,7 +8093,7 @@ "exit": "0.1.x", "htmlparser2": "3.8.x", "lodash": "~4.17.21", - "minimatch": "~3.0.2", + "minimatch": "3.1.5", "strip-json-comments": "1.0.x" }, "dependencies": { @@ -8183,9 +8172,8 @@ "dev": true }, "minimatch": { - "version": "3.0.8", - "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-3.0.8.tgz", - "integrity": "sha512-6FsRAQsxQ61mw+qP1ZzbL9Bc78x2p5OqNgNpnoAFLTrX8n5Kxph0CsnhmKKNXTWjXqU5L0pGPR7hYk+XWZr60Q==", + "version": "3.1.5", + "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-3.1.5.tgz", "dev": true, "requires": { "brace-expansion": "^1.1.7" @@ -8574,7 +8562,7 @@ "browser-stdout": "^1.3.1", "chokidar": "^4.0.1", "debug": "^4.3.5", - "diff": "^7.0.0", + "diff": "^8.0.3", "escape-string-regexp": "^4.0.0", "find-up": "^5.0.0", "glob": "^10.4.5", @@ -8585,7 +8573,7 @@ "minimatch": "^9.0.5", "ms": "^2.1.3", "picocolors": "^1.1.1", - "serialize-javascript": "^6.0.2", + "serialize-javascript": "^7.0.4", "strip-json-comments": "^3.1.1", "supports-color": "^8.1.1", "workerpool": "^9.2.0", @@ -9233,15 +9221,6 @@ "resolved": "https://registry.npmjs.org/quick-lru/-/quick-lru-5.1.1.tgz", "integrity": "sha512-WuyALRjWPDGtt/wzJiadO5AXY+8hZ80hVpe6MyivgraREW751X3SbhRvG3eLKOYN+8VEvqLcf3wdnt44Z4S4SA==" }, - "randombytes": { - "version": "2.1.0", - "resolved": "https://registry.npmjs.org/randombytes/-/randombytes-2.1.0.tgz", - "integrity": "sha512-vYl3iOX+4CKUWuxGi9Ukhie6fsqXqS9FE2Zaic4tNFD2N2QQaXOMFbuKK4QmDHC0JO6B1Zp41J0LpT0oR68amQ==", - "dev": true, - "requires": { - "safe-buffer": "^5.1.0" - } - }, "readdirp": { "version": "4.1.2", "resolved": "https://registry.npmjs.org/readdirp/-/readdirp-4.1.2.tgz", @@ -9389,13 +9368,10 @@ "integrity": "sha512-DrfFnPzblFmNrIZzg5RzHegbiRWg7KMR7btwi2yjHwx06zsUbO5g613sVwEV7FTwmzJu+Io0lJe2GJ3LxqpvBQ==" }, "serialize-javascript": { - "version": "6.0.2", - "resolved": "https://registry.npmjs.org/serialize-javascript/-/serialize-javascript-6.0.2.tgz", - "integrity": "sha512-Saa1xPByTTq2gdeFZYLLo+RFE35NHZkAbqZeWNd3BpzppeVisAqpDjcp8dyf6uIvEqJRd46jemmyA4iFIeVk8g==", - "dev": true, - "requires": { - "randombytes": "^2.1.0" - } + "version": "7.0.4", + "resolved": "https://registry.npmjs.org/serialize-javascript/-/serialize-javascript-7.0.4.tgz", + "integrity": "sha512-DuGdB+Po43Q5Jxwpzt1lhyFSYKryqoNjQSA9M92tyw0lyHIOur+XCalOUe0KTJpyqzT8+fQ5A0Jf7vCx/NKmIg==", + "dev": true }, "set-blocking": { "version": "2.0.0", diff --git a/package.json b/package.json index 41ccc32dc..c5364b333 100644 --- a/package.json +++ b/package.json @@ -47,6 +47,15 @@ "node-gyp": "^11.2.0", "tar-fs": "^3.0.9" }, + "overrides": { + "mocha": { + "diff": "^8.0.3", + "serialize-javascript": "^7.0.4" + }, + "jshint": { + "minimatch": "3.1.5" + } + }, "devDependencies": { "aws-sdk": "^2.1095.0", "clean-for-publish": "~1.0.2", From 6e0c5702ffadcac3d19b95c93e189eb3bc38add0 Mon Sep 17 00:00:00 2001 From: John Alden Date: Tue, 31 Mar 2026 20:53:11 -0700 Subject: [PATCH 3/9] fix: resolve 5 Dependabot security alerts via npm overrides Add and update npm overrides to resolve high and moderate severity vulnerabilities in transitive dependencies: - tar: upgrade to ^7.5.11 (GHSA-9ppj-qmqm-q256, high - symlink path traversal) - picomatch: upgrade to ^4.0.4 (GHSA-c2c7-rcm5-vvqj, high - ReDoS; GHSA-3v7f-55p6-f55p, medium - method injection) - serialize-javascript: upgrade override to ^7.0.5 (GHSA-qj8w-gfj5-8c6v, medium - CPU exhaustion DoS) - brace-expansion: upgrade to ^2.0.3 and ^1.1.13 (GHSA-f886-m6hf-6m8v, medium - process hang and memory exhaustion) Co-Authored-By: Claude Opus 4.6 (1M context) --- package-lock.json | 135 ++++++++++++++++++++-------------------------- package.json | 14 ++++- 2 files changed, 71 insertions(+), 78 deletions(-) diff --git a/package-lock.json b/package-lock.json index 7f1879762..be86a92b9 100644 --- a/package-lock.json +++ b/package-lock.json @@ -858,17 +858,6 @@ } ] }, - "node_modules/brace-expansion": { - "version": "1.1.12", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.12.tgz", - "integrity": "sha512-9T9UjW3r0UW5c1Q7GTwllptXwhvYmEzFhzMfZ9H7FQWt+uZePjZPjBP/W1ZEyZ1twGWom5/56TF4lPcqjnDHcg==", - "dev": true, - "license": "MIT", - "dependencies": { - "balanced-match": "^1.0.0", - "concat-map": "0.0.1" - } - }, "node_modules/browser-stdout": { "version": "1.3.1", "resolved": "https://registry.npmjs.org/browser-stdout/-/browser-stdout-1.3.1.tgz", @@ -952,9 +941,9 @@ } }, "node_modules/cacache/node_modules/brace-expansion": { - "version": "2.0.2", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.0.2.tgz", - "integrity": "sha512-Jt0vHyM+jmUBqojB7E1NIYadt0vI0Qxjxd2TErW94wDz+E2LAm5vKMXXwg6ZZBTHPuUlDgQHKXvjGBdfcF1ZDQ==", + "version": "2.0.3", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.0.3.tgz", + "integrity": "sha512-MCV/fYJEbqx68aE58kv2cA/kiky1G8vux3OR6/jbS+jIMe/6fJWa0DTzJU7dqijOWYwHi1t29FlfYI9uytqlpA==", "license": "MIT", "dependencies": { "balanced-match": "^1.0.0" @@ -3188,17 +3177,6 @@ "integrity": "sha1-ihis/Kmo9Bd+Cav8YDiTmwXR7t8=", "dev": true }, - "node_modules/jshint/node_modules/minimatch": { - "version": "3.1.5", - "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-3.1.5.tgz", - "dev": true, - "dependencies": { - "brace-expansion": "^1.1.7" - }, - "engines": { - "node": "*" - } - }, "node_modules/jshint/node_modules/readable-stream": { "version": "1.1.14", "resolved": "https://registry.npmjs.org/readable-stream/-/readable-stream-1.1.14.tgz", @@ -3556,6 +3534,17 @@ "node": "*" } }, + "node_modules/minimatch/node_modules/brace-expansion": { + "version": "1.1.13", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.13.tgz", + "integrity": "sha512-9ZLprWS6EENmhEOpjCYW2c8VkmOvckIJZfkr7rBW6dObmfgJ/L1GpSYW5Hpo9lDz4D1+n0Ckz8rU7FwHDQiG/w==", + "dev": true, + "license": "MIT", + "dependencies": { + "balanced-match": "^1.0.0", + "concat-map": "0.0.1" + } + }, "node_modules/minimist": { "version": "1.2.7", "resolved": "https://registry.npmjs.org/minimist/-/minimist-1.2.7.tgz", @@ -3737,9 +3726,9 @@ "license": "Python-2.0" }, "node_modules/mocha/node_modules/brace-expansion": { - "version": "2.0.2", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.0.2.tgz", - "integrity": "sha512-Jt0vHyM+jmUBqojB7E1NIYadt0vI0Qxjxd2TErW94wDz+E2LAm5vKMXXwg6ZZBTHPuUlDgQHKXvjGBdfcF1ZDQ==", + "version": "2.0.3", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.0.3.tgz", + "integrity": "sha512-MCV/fYJEbqx68aE58kv2cA/kiky1G8vux3OR6/jbS+jIMe/6fJWa0DTzJU7dqijOWYwHi1t29FlfYI9uytqlpA==", "dev": true, "license": "MIT", "dependencies": { @@ -4502,9 +4491,9 @@ "license": "ISC" }, "node_modules/picomatch": { - "version": "4.0.2", - "resolved": "https://registry.npmjs.org/picomatch/-/picomatch-4.0.2.tgz", - "integrity": "sha512-M7BAV6Rlcy5u+m6oPhAPFgJTzAioX/6B0DxyvDlo9l8+T3nLKbrczg2WLUyzd45L8RqfUMyGPzekbMvX2Ldkwg==", + "version": "4.0.4", + "resolved": "https://registry.npmjs.org/picomatch/-/picomatch-4.0.4.tgz", + "integrity": "sha512-QP88BAKvMam/3NxH6vj2o21R6MjxZUAd6nlwAS/pnGvN9IVLocLHxGYIzFhg6fUQ+5th6P4dv4eW9jX3DSIj7A==", "license": "MIT", "engines": { "node": ">=12" @@ -4865,9 +4854,9 @@ } }, "node_modules/serialize-javascript": { - "version": "7.0.4", - "resolved": "https://registry.npmjs.org/serialize-javascript/-/serialize-javascript-7.0.4.tgz", - "integrity": "sha512-DuGdB+Po43Q5Jxwpzt1lhyFSYKryqoNjQSA9M92tyw0lyHIOur+XCalOUe0KTJpyqzT8+fQ5A0Jf7vCx/NKmIg==", + "version": "7.0.5", + "resolved": "https://registry.npmjs.org/serialize-javascript/-/serialize-javascript-7.0.5.tgz", + "integrity": "sha512-F4LcB0UqUl1zErq+1nYEEzSHJnIwb3AF2XWB94b+afhrekOUijwooAYqFyRbjYkm2PAKBabx6oYv/xDxNi8IBw==", "dev": true, "license": "BSD-3-Clause", "engines": { @@ -5146,9 +5135,9 @@ } }, "node_modules/tar": { - "version": "7.5.10", - "resolved": "https://registry.npmjs.org/tar/-/tar-7.5.10.tgz", - "integrity": "sha512-8mOPs1//5q/rlkNSPcCegA6hiHJYDmSLEI8aMH/CdSQJNWztHC9WHNam5zdQlfpTwB9Xp7IBEsHfV5LKMJGVAw==", + "version": "7.5.13", + "resolved": "https://registry.npmjs.org/tar/-/tar-7.5.13.tgz", + "integrity": "sha512-tOG/7GyXpFevhXVh8jOPJrmtRpOTsYqUIkVdVooZYJS/z8WhfQUX8RJILmeuJNinGAMSu1veBr4asSHFt5/hng==", "license": "BlueOak-1.0.0", "dependencies": { "@isaacs/fs-minipass": "^4.0.0", @@ -6267,7 +6256,7 @@ "node-fetch": "^2.6.7", "nopt": "^8.0.0", "semver": "^7.5.3", - "tar": "^7.4.0" + "tar": "^7.5.11" } }, "@npmcli/agent": { @@ -6470,16 +6459,6 @@ "integrity": "sha512-AKpaYlHn8t4SVbOHCy+b5+KKgvR4vrsD8vbvrbiQJps7fKDTkjkDry6ji0rUJjC0kzbNePLwzxq8iypo41qeWA==", "dev": true }, - "brace-expansion": { - "version": "1.1.12", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.12.tgz", - "integrity": "sha512-9T9UjW3r0UW5c1Q7GTwllptXwhvYmEzFhzMfZ9H7FQWt+uZePjZPjBP/W1ZEyZ1twGWom5/56TF4lPcqjnDHcg==", - "dev": true, - "requires": { - "balanced-match": "^1.0.0", - "concat-map": "0.0.1" - } - }, "browser-stdout": { "version": "1.3.1", "resolved": "https://registry.npmjs.org/browser-stdout/-/browser-stdout-1.3.1.tgz", @@ -6530,14 +6509,14 @@ "minipass-pipeline": "^1.2.4", "p-map": "^7.0.2", "ssri": "^12.0.0", - "tar": "^7.4.3", + "tar": "^7.5.11", "unique-filename": "^4.0.0" }, "dependencies": { "brace-expansion": { - "version": "2.0.2", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.0.2.tgz", - "integrity": "sha512-Jt0vHyM+jmUBqojB7E1NIYadt0vI0Qxjxd2TErW94wDz+E2LAm5vKMXXwg6ZZBTHPuUlDgQHKXvjGBdfcF1ZDQ==", + "version": "2.0.3", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.0.3.tgz", + "integrity": "sha512-MCV/fYJEbqx68aE58kv2cA/kiky1G8vux3OR6/jbS+jIMe/6fJWa0DTzJU7dqijOWYwHi1t29FlfYI9uytqlpA==", "requires": { "balanced-match": "^1.0.0" } @@ -8171,14 +8150,6 @@ "integrity": "sha1-ihis/Kmo9Bd+Cav8YDiTmwXR7t8=", "dev": true }, - "minimatch": { - "version": "3.1.5", - "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-3.1.5.tgz", - "dev": true, - "requires": { - "brace-expansion": "^1.1.7" - } - }, "readable-stream": { "version": "1.1.14", "resolved": "https://registry.npmjs.org/readable-stream/-/readable-stream-1.1.14.tgz", @@ -8456,6 +8427,18 @@ "dev": true, "requires": { "brace-expansion": "^1.1.7" + }, + "dependencies": { + "brace-expansion": { + "version": "1.1.13", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.13.tgz", + "integrity": "sha512-9ZLprWS6EENmhEOpjCYW2c8VkmOvckIJZfkr7rBW6dObmfgJ/L1GpSYW5Hpo9lDz4D1+n0Ckz8rU7FwHDQiG/w==", + "dev": true, + "requires": { + "balanced-match": "^1.0.0", + "concat-map": "0.0.1" + } + } } }, "minimist": { @@ -8573,7 +8556,7 @@ "minimatch": "^9.0.5", "ms": "^2.1.3", "picocolors": "^1.1.1", - "serialize-javascript": "^7.0.4", + "serialize-javascript": "^7.0.5", "strip-json-comments": "^3.1.1", "supports-color": "^8.1.1", "workerpool": "^9.2.0", @@ -8589,9 +8572,9 @@ "dev": true }, "brace-expansion": { - "version": "2.0.2", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.0.2.tgz", - "integrity": "sha512-Jt0vHyM+jmUBqojB7E1NIYadt0vI0Qxjxd2TErW94wDz+E2LAm5vKMXXwg6ZZBTHPuUlDgQHKXvjGBdfcF1ZDQ==", + "version": "2.0.3", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.0.3.tgz", + "integrity": "sha512-MCV/fYJEbqx68aE58kv2cA/kiky1G8vux3OR6/jbS+jIMe/6fJWa0DTzJU7dqijOWYwHi1t29FlfYI9uytqlpA==", "dev": true, "requires": { "balanced-match": "^1.0.0" @@ -8656,7 +8639,7 @@ "integrity": "sha512-OBwBN9AL4dqmETlpS2zasx+vTeWclWzkblfZk7KTA5j3jeOONz/tRCnZomUyvNg83wL5Zv9Ss6HMJXAgL8R2Yg==", "dev": true, "requires": { - "brace-expansion": "^2.0.2" + "brace-expansion": "^2.0.3" } }, "minipass": { @@ -8764,7 +8747,7 @@ "nopt": "^8.0.0", "proc-log": "^5.0.0", "semver": "^7.3.5", - "tar": "^7.4.3", + "tar": "^7.5.11", "tinyglobby": "^0.2.12", "which": "^5.0.0" } @@ -9124,9 +9107,9 @@ "dev": true }, "picomatch": { - "version": "4.0.2", - "resolved": "https://registry.npmjs.org/picomatch/-/picomatch-4.0.2.tgz", - "integrity": "sha512-M7BAV6Rlcy5u+m6oPhAPFgJTzAioX/6B0DxyvDlo9l8+T3nLKbrczg2WLUyzd45L8RqfUMyGPzekbMvX2Ldkwg==" + "version": "4.0.4", + "resolved": "https://registry.npmjs.org/picomatch/-/picomatch-4.0.4.tgz", + "integrity": "sha512-QP88BAKvMam/3NxH6vj2o21R6MjxZUAd6nlwAS/pnGvN9IVLocLHxGYIzFhg6fUQ+5th6P4dv4eW9jX3DSIj7A==" }, "pkg-dir": { "version": "4.2.0", @@ -9368,9 +9351,9 @@ "integrity": "sha512-DrfFnPzblFmNrIZzg5RzHegbiRWg7KMR7btwi2yjHwx06zsUbO5g613sVwEV7FTwmzJu+Io0lJe2GJ3LxqpvBQ==" }, "serialize-javascript": { - "version": "7.0.4", - "resolved": "https://registry.npmjs.org/serialize-javascript/-/serialize-javascript-7.0.4.tgz", - "integrity": "sha512-DuGdB+Po43Q5Jxwpzt1lhyFSYKryqoNjQSA9M92tyw0lyHIOur+XCalOUe0KTJpyqzT8+fQ5A0Jf7vCx/NKmIg==", + "version": "7.0.5", + "resolved": "https://registry.npmjs.org/serialize-javascript/-/serialize-javascript-7.0.5.tgz", + "integrity": "sha512-F4LcB0UqUl1zErq+1nYEEzSHJnIwb3AF2XWB94b+afhrekOUijwooAYqFyRbjYkm2PAKBabx6oYv/xDxNi8IBw==", "dev": true }, "set-blocking": { @@ -9566,9 +9549,9 @@ } }, "tar": { - "version": "7.5.10", - "resolved": "https://registry.npmjs.org/tar/-/tar-7.5.10.tgz", - "integrity": "sha512-8mOPs1//5q/rlkNSPcCegA6hiHJYDmSLEI8aMH/CdSQJNWztHC9WHNam5zdQlfpTwB9Xp7IBEsHfV5LKMJGVAw==", + "version": "7.5.13", + "resolved": "https://registry.npmjs.org/tar/-/tar-7.5.13.tgz", + "integrity": "sha512-tOG/7GyXpFevhXVh8jOPJrmtRpOTsYqUIkVdVooZYJS/z8WhfQUX8RJILmeuJNinGAMSu1veBr4asSHFt5/hng==", "requires": { "@isaacs/fs-minipass": "^4.0.0", "chownr": "^3.0.0", @@ -9703,7 +9686,7 @@ "integrity": "sha512-mEwzpUgrLySlveBwEVDMKk5B57bhLPYovRfPAXD5gA/98Opn0rCDj3GtLwFvCvH5RK9uPCExUROW5NjDwvqkxw==", "requires": { "fdir": "^6.4.4", - "picomatch": "^4.0.2" + "picomatch": "^4.0.4" } }, "to-absolute-glob": { diff --git a/package.json b/package.json index c5364b333..f37ef56b6 100644 --- a/package.json +++ b/package.json @@ -48,12 +48,22 @@ "tar-fs": "^3.0.9" }, "overrides": { + "tar": "^7.5.11", + "picomatch": "^4.0.4", "mocha": { "diff": "^8.0.3", - "serialize-javascript": "^7.0.4" + "serialize-javascript": "^7.0.5", + "brace-expansion": "^2.0.3" + }, + "node-gyp": { + "brace-expansion": "^2.0.3" }, "jshint": { - "minimatch": "3.1.5" + "minimatch": "3.1.5", + "brace-expansion": "^1.1.13" + }, + "clean-for-publish": { + "brace-expansion": "^1.1.13" } }, "devDependencies": { From 4d0adcba8b73652a31bfb2b4a24d2333ed40cc34 Mon Sep 17 00:00:00 2001 From: John Alden Date: Mon, 20 Apr 2026 14:31:27 -0700 Subject: [PATCH 4/9] bump lodash --- package-lock.json | 29 +++++++++++++++++++++-------- package.json | 2 +- 2 files changed, 22 insertions(+), 9 deletions(-) diff --git a/package-lock.json b/package-lock.json index be86a92b9..e14d95d8f 100644 --- a/package-lock.json +++ b/package-lock.json @@ -14,7 +14,7 @@ "fs-extra": "^7.0.0", "got": "^14.4.7", "json5": "^2.1.0", - "lodash": "^4.17.14", + "lodash": "^4.18.1", "nan": "^2.23.1", "node-gyp": "^11.2.0", "tar-fs": "^3.0.9" @@ -3177,6 +3177,13 @@ "integrity": "sha1-ihis/Kmo9Bd+Cav8YDiTmwXR7t8=", "dev": true }, + "node_modules/jshint/node_modules/lodash": { + "version": "4.17.23", + "resolved": "https://registry.npmjs.org/lodash/-/lodash-4.17.23.tgz", + "integrity": "sha512-LgVTMpQtIopCi79SJeDiP0TfWi5CNEc/L/aRdTh3yIvmZXTnheWpKjSZhnvMl8iXbC1tFg9gdHHDMLoV7CnG+w==", + "dev": true, + "license": "MIT" + }, "node_modules/jshint/node_modules/readable-stream": { "version": "1.1.14", "resolved": "https://registry.npmjs.org/readable-stream/-/readable-stream-1.1.14.tgz", @@ -3397,9 +3404,9 @@ } }, "node_modules/lodash": { - "version": "4.17.23", - "resolved": "https://registry.npmjs.org/lodash/-/lodash-4.17.23.tgz", - "integrity": "sha512-LgVTMpQtIopCi79SJeDiP0TfWi5CNEc/L/aRdTh3yIvmZXTnheWpKjSZhnvMl8iXbC1tFg9gdHHDMLoV7CnG+w==", + "version": "4.18.1", + "resolved": "https://registry.npmjs.org/lodash/-/lodash-4.18.1.tgz", + "integrity": "sha512-dMInicTPVE8d1e5otfwmmjlxkZoUpiVLwyeTdUsi/Caj/gfzzblBcCE5sRHV/AsjuCmxWrte2TNGSYuCeCq+0Q==", "license": "MIT" }, "node_modules/lodash.flattendeep": { @@ -8150,6 +8157,12 @@ "integrity": "sha1-ihis/Kmo9Bd+Cav8YDiTmwXR7t8=", "dev": true }, + "lodash": { + "version": "4.17.23", + "resolved": "https://registry.npmjs.org/lodash/-/lodash-4.17.23.tgz", + "integrity": "sha512-LgVTMpQtIopCi79SJeDiP0TfWi5CNEc/L/aRdTh3yIvmZXTnheWpKjSZhnvMl8iXbC1tFg9gdHHDMLoV7CnG+w==", + "dev": true + }, "readable-stream": { "version": "1.1.14", "resolved": "https://registry.npmjs.org/readable-stream/-/readable-stream-1.1.14.tgz", @@ -8337,9 +8350,9 @@ } }, "lodash": { - "version": "4.17.23", - "resolved": "https://registry.npmjs.org/lodash/-/lodash-4.17.23.tgz", - "integrity": "sha512-LgVTMpQtIopCi79SJeDiP0TfWi5CNEc/L/aRdTh3yIvmZXTnheWpKjSZhnvMl8iXbC1tFg9gdHHDMLoV7CnG+w==" + "version": "4.18.1", + "resolved": "https://registry.npmjs.org/lodash/-/lodash-4.18.1.tgz", + "integrity": "sha512-dMInicTPVE8d1e5otfwmmjlxkZoUpiVLwyeTdUsi/Caj/gfzzblBcCE5sRHV/AsjuCmxWrte2TNGSYuCeCq+0Q==" }, "lodash.flattendeep": { "version": "4.4.0", @@ -8426,7 +8439,7 @@ "integrity": "sha512-VgjWUsnnT6n+NUk6eZq77zeFdpW2LWDzP6zFGrCbHXiYNul5Dzqk2HHQ5uFH2DNW5Xbp8+jVzaeNt94ssEEl4w==", "dev": true, "requires": { - "brace-expansion": "^1.1.7" + "brace-expansion": "^1.1.13" }, "dependencies": { "brace-expansion": { diff --git a/package.json b/package.json index f37ef56b6..e0e41d5df 100644 --- a/package.json +++ b/package.json @@ -42,7 +42,7 @@ "fs-extra": "^7.0.0", "got": "^14.4.7", "json5": "^2.1.0", - "lodash": "^4.17.14", + "lodash": "^4.18.1", "nan": "^2.23.1", "node-gyp": "^11.2.0", "tar-fs": "^3.0.9" From 6feda5cff8994cca1bea94c0f824e9bab9d00a79 Mon Sep 17 00:00:00 2001 From: John Alden Date: Mon, 20 Apr 2026 14:38:17 -0700 Subject: [PATCH 5/9] bump to 0.28.0-alpha.37 --- package-lock.json | 4 ++-- package.json | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/package-lock.json b/package-lock.json index e14d95d8f..cd61c7da1 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "nodegit", - "version": "0.28.0-alpha.36", + "version": "0.28.0-alpha.37", "lockfileVersion": 2, "requires": true, "packages": { "": { "name": "nodegit", - "version": "0.28.0-alpha.36", + "version": "0.28.0-alpha.37", "hasInstallScript": true, "license": "MIT", "dependencies": { diff --git a/package.json b/package.json index e0e41d5df..0309ab81e 100644 --- a/package.json +++ b/package.json @@ -1,7 +1,7 @@ { "name": "nodegit", "description": "Node.js libgit2 asynchronous native bindings", - "version": "0.28.0-alpha.36", + "version": "0.28.0-alpha.37", "homepage": "http://nodegit.org", "keywords": [ "libgit2", From 5136a90737948585d5aa2338423b4b5411684285 Mon Sep 17 00:00:00 2001 From: John Alden Date: Tue, 21 Apr 2026 16:17:49 -0700 Subject: [PATCH 6/9] fix v8::Local::GetIsolate deprecation --- generate/templates/manual/src/context.cc | 6 ++---- generate/templates/manual/src/thread_pool.cc | 7 ------- generate/templates/templates/nodegit.cc | 4 +--- 3 files changed, 3 insertions(+), 14 deletions(-) diff --git a/generate/templates/manual/src/context.cc b/generate/templates/manual/src/context.cc index a4c9483dc..a02c40889 100644 --- a/generate/templates/manual/src/context.cc +++ b/generate/templates/manual/src/context.cc @@ -28,7 +28,7 @@ namespace nodegit { : isolate(isolate) , threadPool(10, node::GetCurrentEventLoop(isolate), this) { - Nan::HandleScope scopoe; + Nan::HandleScope scope; v8::Local storage = Nan::New(); persistentStorage.Reset(storage); contexts[isolate] = this; @@ -45,9 +45,7 @@ namespace nodegit { } Context *Context::GetCurrentContext() { - Nan::HandleScope scope; - v8::Local context = Nan::GetCurrentContext(); - v8::Isolate *isolate = context->GetIsolate(); + v8::Isolate *isolate = v8::Isolate::GetCurrent(); return contexts[isolate]; } diff --git a/generate/templates/manual/src/thread_pool.cc b/generate/templates/manual/src/thread_pool.cc index 4cd5c095a..0aacdf280 100644 --- a/generate/templates/manual/src/thread_pool.cc +++ b/generate/templates/manual/src/thread_pool.cc @@ -657,9 +657,6 @@ namespace nodegit { // NOTE this should theoretically never be triggered during a cleanup operation void ThreadPoolImpl::RunLoopCallbacks() { - Nan::HandleScope scope; - v8::Local context = Nan::GetCurrentContext(); - node::CallbackScope callbackScope(context->GetIsolate(), Nan::New(), {0, 0}); std::unique_lock lock(*jsThreadCallbackMutex); // get the next callback to run @@ -719,10 +716,6 @@ namespace nodegit { orchestratorJobCondition.notify_all(); } - Nan::HandleScope scope; - v8::Local context = Nan::GetCurrentContext(); - node::CallbackScope callbackScope(context->GetIsolate(), Nan::New(), {0, 0}); - while (cancelledJobs.size()) { std::shared_ptr cancelledJob = cancelledJobs.front(); std::shared_ptr asyncWorkJob = std::static_pointer_cast(cancelledJob); diff --git a/generate/templates/templates/nodegit.cc b/generate/templates/templates/nodegit.cc index e43f8b2ae..afcfac228 100644 --- a/generate/templates/templates/nodegit.cc +++ b/generate/templates/templates/nodegit.cc @@ -101,9 +101,7 @@ NAN_MODULE_INIT(init) { , Nan::GetFunction(Nan::New(GetNumberOfTrackedObjects)).ToLocalChecked() ); - Nan::HandleScope scope; - Local context = Nan::GetCurrentContext(); - Isolate *isolate = context->GetIsolate(); + Isolate *isolate = v8::Isolate::GetCurrent(); nodegit::Context *nodegitContext = new nodegit::Context(isolate); Wrapper::InitializeComponent(target, nodegitContext); From 9167b9cc77f253260c8a6d6ab9819dff9aaedc4c Mon Sep 17 00:00:00 2001 From: John Alden Date: Tue, 21 Apr 2026 16:23:29 -0700 Subject: [PATCH 7/9] fix v::PropertyCallbackInfo::This() deprecation --- .../templates/manual/filter_source/repo.cc | 4 +- generate/templates/manual/remote/ls.cc | 4 +- .../manual/repository/get_references.cc | 4 +- .../manual/repository/get_remotes.cc | 4 +- .../manual/repository/get_submodules.cc | 4 +- .../manual/repository/refresh_references.cc | 4 +- .../templates/manual/repository/statistics.cc | 4 +- .../templates/manual/revwalk/commit_walk.cc | 4 +- .../templates/manual/revwalk/fast_walk.cc | 4 +- .../manual/revwalk/file_history_walk.cc | 4 +- .../templates/manual/src/convenient_hunk.cc | 22 +++++----- .../templates/manual/src/convenient_patch.cc | 40 +++++++++---------- .../templates/manual/src/nodegit_wrapper.cc | 4 +- .../manual/src/promise_completion.cc | 6 +-- generate/templates/manual/src/wrapper.cc | 6 +-- .../manual/tree/get_all_filepaths.cc | 4 +- generate/templates/partials/async_function.cc | 4 +- generate/templates/partials/convert_to_v8.cc | 2 +- .../templates/partials/field_accessors.cc | 4 +- generate/templates/partials/fields.cc | 4 +- generate/templates/partials/sync_function.cc | 10 ++--- package-lock.json | 13 +++--- package.json | 2 +- 23 files changed, 80 insertions(+), 81 deletions(-) diff --git a/generate/templates/manual/filter_source/repo.cc b/generate/templates/manual/filter_source/repo.cc index 78903d86b..eddcf8154 100644 --- a/generate/templates/manual/filter_source/repo.cc +++ b/generate/templates/manual/filter_source/repo.cc @@ -16,13 +16,13 @@ NAN_METHOD(GitFilterSource::Repo) { baton->error_code = GIT_OK; baton->error = NULL; - baton->src = Nan::ObjectWrap::Unwrap(info.This())->GetValue(); + baton->src = Nan::ObjectWrap::Unwrap(info.Holder())->GetValue(); Nan::Callback *callback = new Nan::Callback(v8::Local::Cast(info[info.Length() - 1])); std::map> cleanupHandles; RepoWorker *worker = new RepoWorker(baton, callback, cleanupHandles); - worker->Reference("src", info.This()); + worker->Reference("src", info.Holder()); nodegit::Context *nodegitContext = reinterpret_cast(info.Data().As()->Value()); nodegitContext->QueueWorker(worker); diff --git a/generate/templates/manual/remote/ls.cc b/generate/templates/manual/remote/ls.cc index 97c801c62..b22d87afd 100644 --- a/generate/templates/manual/remote/ls.cc +++ b/generate/templates/manual/remote/ls.cc @@ -9,12 +9,12 @@ NAN_METHOD(GitRemote::ReferenceList) baton->error_code = GIT_OK; baton->error = NULL; baton->out = new std::vector; - baton->remote = Nan::ObjectWrap::Unwrap(info.This())->GetValue(); + baton->remote = Nan::ObjectWrap::Unwrap(info.Holder())->GetValue(); Nan::Callback *callback = new Nan::Callback(Local::Cast(info[info.Length() - 1])); std::map> cleanupHandles; ReferenceListWorker *worker = new ReferenceListWorker(baton, callback, cleanupHandles); - worker->Reference("remote", info.This()); + worker->Reference("remote", info.Holder()); nodegit::Context *nodegitContext = reinterpret_cast(info.Data().As()->Value()); nodegitContext->QueueWorker(worker); return; diff --git a/generate/templates/manual/repository/get_references.cc b/generate/templates/manual/repository/get_references.cc index 56bc12ac3..47db9f467 100644 --- a/generate/templates/manual/repository/get_references.cc +++ b/generate/templates/manual/repository/get_references.cc @@ -9,12 +9,12 @@ NAN_METHOD(GitRepository::GetReferences) baton->error_code = GIT_OK; baton->error = NULL; baton->out = new std::vector; - baton->repo = Nan::ObjectWrap::Unwrap(info.This())->GetValue(); + baton->repo = Nan::ObjectWrap::Unwrap(info.Holder())->GetValue(); Nan::Callback *callback = new Nan::Callback(Local::Cast(info[info.Length() - 1])); std::map> cleanupHandles; GetReferencesWorker *worker = new GetReferencesWorker(baton, callback, cleanupHandles); - worker->Reference("repo", info.This()); + worker->Reference("repo", info.Holder()); nodegit::Context *nodegitContext = reinterpret_cast(info.Data().As()->Value()); nodegitContext->QueueWorker(worker); return; diff --git a/generate/templates/manual/repository/get_remotes.cc b/generate/templates/manual/repository/get_remotes.cc index a7c316bb0..779dd37a2 100644 --- a/generate/templates/manual/repository/get_remotes.cc +++ b/generate/templates/manual/repository/get_remotes.cc @@ -9,12 +9,12 @@ NAN_METHOD(GitRepository::GetRemotes) baton->error_code = GIT_OK; baton->error = NULL; baton->out = new std::vector; - baton->repo = Nan::ObjectWrap::Unwrap(info.This())->GetValue(); + baton->repo = Nan::ObjectWrap::Unwrap(info.Holder())->GetValue(); Nan::Callback *callback = new Nan::Callback(Local::Cast(info[info.Length() - 1])); std::map> cleanupHandles; GetRemotesWorker *worker = new GetRemotesWorker(baton, callback, cleanupHandles); - worker->Reference("repo", info.This()); + worker->Reference("repo", info.Holder()); nodegit::Context *nodegitContext = reinterpret_cast(info.Data().As()->Value()); nodegitContext->QueueWorker(worker); return; diff --git a/generate/templates/manual/repository/get_submodules.cc b/generate/templates/manual/repository/get_submodules.cc index 069f6bdbc..1c79e6257 100644 --- a/generate/templates/manual/repository/get_submodules.cc +++ b/generate/templates/manual/repository/get_submodules.cc @@ -9,12 +9,12 @@ NAN_METHOD(GitRepository::GetSubmodules) baton->error_code = GIT_OK; baton->error = NULL; baton->out = new std::vector; - baton->repo = Nan::ObjectWrap::Unwrap(info.This())->GetValue(); + baton->repo = Nan::ObjectWrap::Unwrap(info.Holder())->GetValue(); Nan::Callback *callback = new Nan::Callback(Local::Cast(info[info.Length() - 1])); std::map> cleanupHandles; GetSubmodulesWorker *worker = new GetSubmodulesWorker(baton, callback, cleanupHandles); - worker->Reference("repo", info.This()); + worker->Reference("repo", info.Holder()); nodegit::Context *nodegitContext = reinterpret_cast(info.Data().As()->Value()); nodegitContext->QueueWorker(worker); return; diff --git a/generate/templates/manual/repository/refresh_references.cc b/generate/templates/manual/repository/refresh_references.cc index 5194f1c48..e6913fa98 100644 --- a/generate/templates/manual/repository/refresh_references.cc +++ b/generate/templates/manual/repository/refresh_references.cc @@ -416,12 +416,12 @@ NAN_METHOD(GitRepository::RefreshReferences) baton->error_code = GIT_OK; baton->error = NULL; baton->out = (void *)new RefreshReferencesData(); - baton->repo = Nan::ObjectWrap::Unwrap(info.This())->GetValue(); + baton->repo = Nan::ObjectWrap::Unwrap(info.Holder())->GetValue(); Nan::Callback *callback = new Nan::Callback(Local::Cast(info[info.Length() - 1])); std::map> cleanupHandles; RefreshReferencesWorker *worker = new RefreshReferencesWorker(baton, callback, cleanupHandles); - worker->Reference("repo", info.This()); + worker->Reference("repo", info.Holder()); worker->Reference("signatureType", signatureType); nodegit::Context *nodegitContext = reinterpret_cast(info.Data().As()->Value()); nodegitContext->QueueWorker(worker); diff --git a/generate/templates/manual/repository/statistics.cc b/generate/templates/manual/repository/statistics.cc index f438bb5f8..2cc188ff9 100644 --- a/generate/templates/manual/repository/statistics.cc +++ b/generate/templates/manual/repository/statistics.cc @@ -1781,13 +1781,13 @@ NAN_METHOD(GitRepository::Statistics) baton->error_code = GIT_OK; baton->error = NULL; - baton->repo = Nan::ObjectWrap::Unwrap(info.This())->GetValue(); + baton->repo = Nan::ObjectWrap::Unwrap(info.Holder())->GetValue(); baton->out = static_cast(new RepoAnalysis(baton->repo)); Nan::Callback *callback = new Nan::Callback(Local::Cast(info[info.Length() - 1])); std::map> cleanupHandles; StatisticsWorker *worker = new StatisticsWorker(baton, callback, cleanupHandles); - worker->Reference("repo", info.This()); + worker->Reference("repo", info.Holder()); nodegit::Context *nodegitContext = reinterpret_cast(info.Data().As()->Value()); nodegitContext->QueueWorker(worker); diff --git a/generate/templates/manual/revwalk/commit_walk.cc b/generate/templates/manual/revwalk/commit_walk.cc index 4fe60de9e..cec7ff2f0 100644 --- a/generate/templates/manual/revwalk/commit_walk.cc +++ b/generate/templates/manual/revwalk/commit_walk.cc @@ -139,11 +139,11 @@ NAN_METHOD(GitRevwalk::CommitWalk) { } else { baton->returnPlainObjects = false; } - baton->walk = Nan::ObjectWrap::Unwrap(info.This())->GetValue(); + baton->walk = Nan::ObjectWrap::Unwrap(info.Holder())->GetValue(); Nan::Callback *callback = new Nan::Callback(Local::Cast(info[info.Length() - 1])); std::map> cleanupHandles; CommitWalkWorker *worker = new CommitWalkWorker(baton, callback, cleanupHandles); - worker->Reference("commitWalk", info.This()); + worker->Reference("commitWalk", info.Holder()); nodegit::Context *nodegitContext = reinterpret_cast(info.Data().As()->Value()); nodegitContext->QueueWorker(worker); diff --git a/generate/templates/manual/revwalk/fast_walk.cc b/generate/templates/manual/revwalk/fast_walk.cc index ce2d05a2d..2aa03620b 100644 --- a/generate/templates/manual/revwalk/fast_walk.cc +++ b/generate/templates/manual/revwalk/fast_walk.cc @@ -15,12 +15,12 @@ NAN_METHOD(GitRevwalk::FastWalk) baton->max_count = Nan::To(info[0]).FromJust(); baton->out = new std::vector; baton->out->reserve(baton->max_count); - baton->walk = Nan::ObjectWrap::Unwrap(info.This())->GetValue(); + baton->walk = Nan::ObjectWrap::Unwrap(info.Holder())->GetValue(); Nan::Callback *callback = new Nan::Callback(Local::Cast(info[info.Length() - 1])); std::map> cleanupHandles; FastWalkWorker *worker = new FastWalkWorker(baton, callback, cleanupHandles); - worker->Reference("fastWalk", info.This()); + worker->Reference("fastWalk", info.Holder()); nodegit::Context *nodegitContext = reinterpret_cast(info.Data().As()->Value()); nodegitContext->QueueWorker(worker); diff --git a/generate/templates/manual/revwalk/file_history_walk.cc b/generate/templates/manual/revwalk/file_history_walk.cc index 569bb022d..25ac40ed8 100644 --- a/generate/templates/manual/revwalk/file_history_walk.cc +++ b/generate/templates/manual/revwalk/file_history_walk.cc @@ -214,12 +214,12 @@ NAN_METHOD(GitRevwalk::FileHistoryWalk) baton->max_count = Nan::To(info[1]).FromJust(); baton->out = new std::vector; baton->out->reserve(baton->max_count); - baton->walk = Nan::ObjectWrap::Unwrap(info.This())->GetValue(); + baton->walk = Nan::ObjectWrap::Unwrap(info.Holder())->GetValue(); Nan::Callback *callback = new Nan::Callback(Local::Cast(info[info.Length() - 1])); std::map> cleanupHandles; FileHistoryWalkWorker *worker = new FileHistoryWalkWorker(baton, callback, cleanupHandles); - worker->Reference("fileHistoryWalk", info.This()); + worker->Reference("fileHistoryWalk", info.Holder()); nodegit::Context *nodegitContext = reinterpret_cast(info.Data().As()->Value()); nodegitContext->QueueWorker(worker); diff --git a/generate/templates/manual/src/convenient_hunk.cc b/generate/templates/manual/src/convenient_hunk.cc index 2d33e50b6..3fb095dc9 100644 --- a/generate/templates/manual/src/convenient_hunk.cc +++ b/generate/templates/manual/src/convenient_hunk.cc @@ -64,9 +64,9 @@ NAN_METHOD(ConvenientHunk::JSNewFunction) { } ConvenientHunk* object = new ConvenientHunk(static_cast(Local::Cast(info[0])->Value())); - object->Wrap(info.This()); + object->Wrap(info.Holder()); - info.GetReturnValue().Set(info.This()); + info.GetReturnValue().Set(info.Holder()); } Local ConvenientHunk::New(void *raw) { @@ -87,7 +87,7 @@ size_t ConvenientHunk::GetSize() { NAN_METHOD(ConvenientHunk::Size) { Local to; - to = Nan::New(Nan::ObjectWrap::Unwrap(info.This())->GetSize()); + to = Nan::New(Nan::ObjectWrap::Unwrap(info.Holder())->GetSize()); info.GetReturnValue().Set(to); } @@ -98,14 +98,14 @@ NAN_METHOD(ConvenientHunk::Lines) { LinesBaton *baton = new LinesBaton(); - baton->hunk = Nan::ObjectWrap::Unwrap(info.This())->GetValue(); + baton->hunk = Nan::ObjectWrap::Unwrap(info.Holder())->GetValue(); baton->lines = new std::vector; baton->lines->reserve(baton->hunk->numLines); Nan::Callback *callback = new Nan::Callback(Local::Cast(info[0])); LinesWorker *worker = new LinesWorker(baton, callback); - worker->Reference("hunk", info.This()); + worker->Reference("hunk", info.Holder()); nodegit::Context *nodegitContext = reinterpret_cast(info.Data().As()->Value()); nodegitContext->QueueWorker(worker); @@ -160,39 +160,39 @@ void ConvenientHunk::LinesWorker::HandleOKCallback() { NAN_METHOD(ConvenientHunk::OldStart) { Local to; - int old_start = Nan::ObjectWrap::Unwrap(info.This())->GetValue()->hunk.old_start; + int old_start = Nan::ObjectWrap::Unwrap(info.Holder())->GetValue()->hunk.old_start; info.GetReturnValue().Set(Nan::New(old_start)); } NAN_METHOD(ConvenientHunk::OldLines) { Local to; - int old_lines = Nan::ObjectWrap::Unwrap(info.This())->GetValue()->hunk.old_lines; + int old_lines = Nan::ObjectWrap::Unwrap(info.Holder())->GetValue()->hunk.old_lines; info.GetReturnValue().Set(Nan::New(old_lines)); } NAN_METHOD(ConvenientHunk::NewStart) { Local to; - int new_start = Nan::ObjectWrap::Unwrap(info.This())->GetValue()->hunk.new_start; + int new_start = Nan::ObjectWrap::Unwrap(info.Holder())->GetValue()->hunk.new_start; info.GetReturnValue().Set(Nan::New(new_start)); } NAN_METHOD(ConvenientHunk::NewLines) { Local to; - int new_lines = Nan::ObjectWrap::Unwrap(info.This())->GetValue()->hunk.new_lines; + int new_lines = Nan::ObjectWrap::Unwrap(info.Holder())->GetValue()->hunk.new_lines; info.GetReturnValue().Set(Nan::New(new_lines)); } NAN_METHOD(ConvenientHunk::HeaderLen) { Local to; - size_t header_len = Nan::ObjectWrap::Unwrap(info.This())->GetValue()->hunk.header_len; + size_t header_len = Nan::ObjectWrap::Unwrap(info.Holder())->GetValue()->hunk.header_len; info.GetReturnValue().Set(Nan::New(header_len)); } NAN_METHOD(ConvenientHunk::Header) { Local to; - char *header = Nan::ObjectWrap::Unwrap(info.This())->GetValue()->hunk.header; + char *header = Nan::ObjectWrap::Unwrap(info.Holder())->GetValue()->hunk.header; if (header) { to = Nan::New(header).ToLocalChecked(); } else { diff --git a/generate/templates/manual/src/convenient_patch.cc b/generate/templates/manual/src/convenient_patch.cc index 22e6e6b49..771aede85 100644 --- a/generate/templates/manual/src/convenient_patch.cc +++ b/generate/templates/manual/src/convenient_patch.cc @@ -170,9 +170,9 @@ NAN_METHOD(ConvenientPatch::JSNewFunction) { } ConvenientPatch* object = new ConvenientPatch(static_cast(Local::Cast(info[0])->Value())); - object->Wrap(info.This()); + object->Wrap(info.Holder()); - info.GetReturnValue().Set(info.This()); + info.GetReturnValue().Set(info.Holder()); } Local ConvenientPatch::New(void *raw) { @@ -214,14 +214,14 @@ NAN_METHOD(ConvenientPatch::Hunks) { HunksBaton *baton = new HunksBaton(); - baton->patch = Nan::ObjectWrap::Unwrap(info.This())->GetValue(); + baton->patch = Nan::ObjectWrap::Unwrap(info.Holder())->GetValue(); baton->hunks = new std::vector; baton->hunks->reserve(baton->patch->numHunks); Nan::Callback *callback = new Nan::Callback(Local::Cast(info[0])); HunksWorker *worker = new HunksWorker(baton, callback); - worker->Reference("patch", info.This()); + worker->Reference("patch", info.Holder()); nodegit::Context *nodegitContext = reinterpret_cast(info.Data().As()->Value()); nodegitContext->QueueWorker(worker); @@ -300,7 +300,7 @@ NAN_METHOD(ConvenientPatch::LineStats) { Local to; Local toReturn = Nan::New(); - ConvenientLineStats stats = Nan::ObjectWrap::Unwrap(info.This())->GetLineStats(); + ConvenientLineStats stats = Nan::ObjectWrap::Unwrap(info.Holder())->GetLineStats(); to = Nan::New(stats.context); Nan::Set(toReturn, Nan::New("total_context").ToLocalChecked(), to); @@ -315,7 +315,7 @@ NAN_METHOD(ConvenientPatch::LineStats) { NAN_METHOD(ConvenientPatch::Size) { Local to; - to = Nan::New(Nan::ObjectWrap::Unwrap(info.This())->GetNumHunks()); + to = Nan::New(Nan::ObjectWrap::Unwrap(info.Holder())->GetNumHunks()); info.GetReturnValue().Set(to); } @@ -325,7 +325,7 @@ NAN_METHOD(ConvenientPatch::OldFile) { Local to; git_diff_file *old_file = (git_diff_file *)malloc(sizeof(git_diff_file)); - *old_file = Nan::ObjectWrap::Unwrap(info.This())->GetOldFile(); + *old_file = Nan::ObjectWrap::Unwrap(info.Holder())->GetOldFile(); to = GitDiffFile::New(old_file, true); @@ -337,7 +337,7 @@ NAN_METHOD(ConvenientPatch::NewFile) { Local to; git_diff_file *new_file = (git_diff_file *)malloc(sizeof(git_diff_file)); - *new_file = Nan::ObjectWrap::Unwrap(info.This())->GetNewFile(); + *new_file = Nan::ObjectWrap::Unwrap(info.Holder())->GetNewFile(); if (new_file != NULL) { to = GitDiffFile::New(new_file, true); } else { @@ -349,7 +349,7 @@ NAN_METHOD(ConvenientPatch::NewFile) { NAN_METHOD(ConvenientPatch::Status) { Local to; - to = Nan::New(Nan::ObjectWrap::Unwrap(info.This())->GetStatus()); + to = Nan::New(Nan::ObjectWrap::Unwrap(info.Holder())->GetStatus()); info.GetReturnValue().Set(to); } @@ -357,67 +357,67 @@ NAN_METHOD(ConvenientPatch::IsUnmodified) { Nan::EscapableHandleScope scope; Local to; - to = Nan::New(Nan::ObjectWrap::Unwrap(info.This())->GetStatus() == GIT_DELTA_UNMODIFIED); + to = Nan::New(Nan::ObjectWrap::Unwrap(info.Holder())->GetStatus() == GIT_DELTA_UNMODIFIED); info.GetReturnValue().Set(to); } NAN_METHOD(ConvenientPatch::IsAdded) { Local to; - to = Nan::New(Nan::ObjectWrap::Unwrap(info.This())->GetStatus() == GIT_DELTA_ADDED); + to = Nan::New(Nan::ObjectWrap::Unwrap(info.Holder())->GetStatus() == GIT_DELTA_ADDED); info.GetReturnValue().Set(to); } NAN_METHOD(ConvenientPatch::IsDeleted) { Local to; - to = Nan::New(Nan::ObjectWrap::Unwrap(info.This())->GetStatus() == GIT_DELTA_DELETED); + to = Nan::New(Nan::ObjectWrap::Unwrap(info.Holder())->GetStatus() == GIT_DELTA_DELETED); info.GetReturnValue().Set(to); } NAN_METHOD(ConvenientPatch::IsModified) { Local to; - to = Nan::New(Nan::ObjectWrap::Unwrap(info.This())->GetStatus() == GIT_DELTA_MODIFIED); + to = Nan::New(Nan::ObjectWrap::Unwrap(info.Holder())->GetStatus() == GIT_DELTA_MODIFIED); info.GetReturnValue().Set(to); } NAN_METHOD(ConvenientPatch::IsRenamed) { Local to; - to = Nan::New(Nan::ObjectWrap::Unwrap(info.This())->GetStatus() == GIT_DELTA_RENAMED); + to = Nan::New(Nan::ObjectWrap::Unwrap(info.Holder())->GetStatus() == GIT_DELTA_RENAMED); info.GetReturnValue().Set(to); } NAN_METHOD(ConvenientPatch::IsCopied) { Local to; - to = Nan::New(Nan::ObjectWrap::Unwrap(info.This())->GetStatus() == GIT_DELTA_COPIED); + to = Nan::New(Nan::ObjectWrap::Unwrap(info.Holder())->GetStatus() == GIT_DELTA_COPIED); info.GetReturnValue().Set(to); } NAN_METHOD(ConvenientPatch::IsIgnored) { Local to; - to = Nan::New(Nan::ObjectWrap::Unwrap(info.This())->GetStatus() == GIT_DELTA_IGNORED); + to = Nan::New(Nan::ObjectWrap::Unwrap(info.Holder())->GetStatus() == GIT_DELTA_IGNORED); info.GetReturnValue().Set(to); } NAN_METHOD(ConvenientPatch::IsUntracked) { Local to; - to = Nan::New(Nan::ObjectWrap::Unwrap(info.This())->GetStatus() == GIT_DELTA_UNTRACKED); + to = Nan::New(Nan::ObjectWrap::Unwrap(info.Holder())->GetStatus() == GIT_DELTA_UNTRACKED); info.GetReturnValue().Set(to); } NAN_METHOD(ConvenientPatch::IsTypeChange) { Local to; - to = Nan::New(Nan::ObjectWrap::Unwrap(info.This())->GetStatus() == GIT_DELTA_TYPECHANGE); + to = Nan::New(Nan::ObjectWrap::Unwrap(info.Holder())->GetStatus() == GIT_DELTA_TYPECHANGE); info.GetReturnValue().Set(to); } NAN_METHOD(ConvenientPatch::IsUnreadable) { Local to; - to = Nan::New(Nan::ObjectWrap::Unwrap(info.This())->GetStatus() == GIT_DELTA_UNREADABLE); + to = Nan::New(Nan::ObjectWrap::Unwrap(info.Holder())->GetStatus() == GIT_DELTA_UNREADABLE); info.GetReturnValue().Set(to); } NAN_METHOD(ConvenientPatch::IsConflicted) { Local to; - to = Nan::New(Nan::ObjectWrap::Unwrap(info.This())->GetStatus() == GIT_DELTA_CONFLICTED); + to = Nan::New(Nan::ObjectWrap::Unwrap(info.Holder())->GetStatus() == GIT_DELTA_CONFLICTED); info.GetReturnValue().Set(to); } diff --git a/generate/templates/manual/src/nodegit_wrapper.cc b/generate/templates/manual/src/nodegit_wrapper.cc index a790d7bc3..b687a200e 100644 --- a/generate/templates/manual/src/nodegit_wrapper.cc +++ b/generate/templates/manual/src/nodegit_wrapper.cc @@ -79,8 +79,8 @@ NAN_METHOD(NodeGitWrapper::JSNewFunction) { ); } - instance->Wrap(info.This()); - info.GetReturnValue().Set(info.This()); + instance->Wrap(info.Holder()); + info.GetReturnValue().Set(info.Holder()); } template diff --git a/generate/templates/manual/src/promise_completion.cc b/generate/templates/manual/src/promise_completion.cc index d3e4f4426..75d7c483b 100644 --- a/generate/templates/manual/src/promise_completion.cc +++ b/generate/templates/manual/src/promise_completion.cc @@ -57,8 +57,8 @@ bool PromiseCompletion::ForwardIfPromise(v8::Local result, nodegit::A // creates a new instance of PromiseCompletion, wrapped in a v8 object NAN_METHOD(PromiseCompletion::New) { PromiseCompletion *promiseCompletion = new PromiseCompletion(); - promiseCompletion->Wrap(info.This()); - info.GetReturnValue().Set(info.This()); + promiseCompletion->Wrap(info.Holder()); + info.GetReturnValue().Set(info.Holder()); } // sets up a Promise to forward the promise result via the baton and callback @@ -107,7 +107,7 @@ void PromiseCompletion::CallCallback(bool isFulfilled, const Nan::FunctionCallba resultOfPromise = info[0]; } - PromiseCompletion *promiseCompletion = ObjectWrap::Unwrap(Nan::To(info.This()).ToLocalChecked()); + PromiseCompletion *promiseCompletion = ObjectWrap::Unwrap(Nan::To(info.Holder()).ToLocalChecked()); (*promiseCompletion->callback)(isFulfilled, promiseCompletion->baton, resultOfPromise); } diff --git a/generate/templates/manual/src/wrapper.cc b/generate/templates/manual/src/wrapper.cc index 3bad23c7d..377482ca0 100644 --- a/generate/templates/manual/src/wrapper.cc +++ b/generate/templates/manual/src/wrapper.cc @@ -39,9 +39,9 @@ NAN_METHOD(Wrapper::JSNewFunction) { } Wrapper* object = new Wrapper(External::Cast(*info[0])->Value()); - object->Wrap(info.This()); + object->Wrap(info.Holder()); - info.GetReturnValue().Set(info.This()); + info.GetReturnValue().Set(info.Holder()); } Local Wrapper::New(const void *raw) { @@ -74,7 +74,7 @@ NAN_METHOD(Wrapper::ToBuffer) { Local constructorArgs[1] = { Nan::New(len) }; Local nodeBuffer = Nan::NewInstance(bufferConstructor, 1, constructorArgs).ToLocalChecked(); - std::memcpy(node::Buffer::Data(nodeBuffer), Nan::ObjectWrap::Unwrap(info.This())->GetValue(), len); + std::memcpy(node::Buffer::Data(nodeBuffer), Nan::ObjectWrap::Unwrap(info.Holder())->GetValue(), len); info.GetReturnValue().Set(nodeBuffer); } diff --git a/generate/templates/manual/tree/get_all_filepaths.cc b/generate/templates/manual/tree/get_all_filepaths.cc index 758383980..839589e0c 100644 --- a/generate/templates/manual/tree/get_all_filepaths.cc +++ b/generate/templates/manual/tree/get_all_filepaths.cc @@ -43,14 +43,14 @@ NAN_METHOD(GitTree::GetAllFilepaths) baton->error_code = GIT_OK; baton->error = NULL; - baton->tree = Nan::ObjectWrap::Unwrap(info.This())->GetValue(); + baton->tree = Nan::ObjectWrap::Unwrap(info.Holder())->GetValue(); baton->out = new std::vector; baton->repo = git_tree_owner(baton->tree); Nan::Callback *callback = new Nan::Callback(Local::Cast(info[info.Length() - 1])); std::map> cleanupHandles; GetAllFilepathsWorker *worker = new GetAllFilepathsWorker(baton, callback, cleanupHandles); - worker->Reference("tree", info.This()); + worker->Reference("tree", info.Holder()); nodegit::Context *nodegitContext = reinterpret_cast(info.Data().As()->Value()); nodegitContext->QueueWorker(worker); diff --git a/generate/templates/partials/async_function.cc b/generate/templates/partials/async_function.cc index d23ec7f60..deb37abf2 100644 --- a/generate/templates/partials/async_function.cc +++ b/generate/templates/partials/async_function.cc @@ -23,7 +23,7 @@ NAN_METHOD({{ cppClassName }}::{{ cppFunctionName }}) { {%each args|argsInfo as arg %} {%if not arg.isReturn %} {%if arg.isSelf %} - baton->{{ arg.name }} = Nan::ObjectWrap::Unwrap<{{ arg.cppClassName }}>(info.This())->GetValue(); + baton->{{ arg.name }} = Nan::ObjectWrap::Unwrap<{{ arg.cppClassName }}>(info.Holder())->GetValue(); {%elsif arg.isCallbackFunction %} if (!info[{{ arg.jsArg }}]->IsFunction()) { baton->{{ arg.name }} = NULL; @@ -110,7 +110,7 @@ NAN_METHOD({{ cppClassName }}::{{ cppFunctionName }}) { {%each args|argsInfo as arg %} {%if not arg.isReturn %} {%if arg.isSelf %} - worker->Reference<{{ arg.cppClassName }}>("{{ arg.name }}", info.This()); + worker->Reference<{{ arg.cppClassName }}>("{{ arg.name }}", info.Holder()); {%elsif not arg.isCallbackFunction %} {%if arg.isUnwrappable %} {% if arg.cppClassName == "Array" %} diff --git a/generate/templates/partials/convert_to_v8.cc b/generate/templates/partials/convert_to_v8.cc index ccba9b330..f24f86ecb 100644 --- a/generate/templates/partials/convert_to_v8.cc +++ b/generate/templates/partials/convert_to_v8.cc @@ -102,7 +102,7 @@ {%if isAsync %} {% elsif ownedByThis %} {%-- If the owner of this object is "this", it will be retrievable from the info object in a sync method. --%} - Nan::Set(owners, owners->Length(), info.This()); + Nan::Set(owners, owners->Length(), info.Holder()); {% endif %} {% if ownerFn | toBool %} Nan::Set( diff --git a/generate/templates/partials/field_accessors.cc b/generate/templates/partials/field_accessors.cc index bcd5e5f87..26d454636 100644 --- a/generate/templates/partials/field_accessors.cc +++ b/generate/templates/partials/field_accessors.cc @@ -2,7 +2,7 @@ {% if not field.ignore %} NAN_GETTER({{ cppClassName }}::Get{{ field.cppFunctionName }}) { - {{ cppClassName }} *wrapper = Nan::ObjectWrap::Unwrap<{{ cppClassName }}>(info.This()); + {{ cppClassName }} *wrapper = Nan::ObjectWrap::Unwrap<{{ cppClassName }}>(info.Holder()); {% if field.isEnum %} info.GetReturnValue().Set(Nan::New((int)wrapper->GetValue()->{{ field.name }})); @@ -24,7 +24,7 @@ } NAN_SETTER({{ cppClassName }}::Set{{ field.cppFunctionName }}) { - {{ cppClassName }} *wrapper = Nan::ObjectWrap::Unwrap<{{ cppClassName }}>(info.This()); + {{ cppClassName }} *wrapper = Nan::ObjectWrap::Unwrap<{{ cppClassName }}>(info.Holder()); {% if field.isEnum %} if (value->IsNumber()) { diff --git a/generate/templates/partials/fields.cc b/generate/templates/partials/fields.cc index d9478549e..31b035daa 100644 --- a/generate/templates/partials/fields.cc +++ b/generate/templates/partials/fields.cc @@ -5,7 +5,7 @@ v8::Local v8ConversionSlot; {% if field | isFixedLengthString %} - char* {{ field.name }} = (char *)Nan::ObjectWrap::Unwrap<{{ cppClassName }}>(info.This())->GetValue()->{{ field.name }}; + char* {{ field.name }} = (char *)Nan::ObjectWrap::Unwrap<{{ cppClassName }}>(info.Holder())->GetValue()->{{ field.name }}; {% else %} {% if field.cType|isArrayType %} {{ field.cType|arrayTypeToPlainType }} *{{ field.name }} = @@ -21,7 +21,7 @@ {% endif %} {% endif %} {% endif %} - Nan::ObjectWrap::Unwrap<{{ cppClassName }}>(info.This())->GetValue()->{{ field.name }}; + Nan::ObjectWrap::Unwrap<{{ cppClassName }}>(info.Holder())->GetValue()->{{ field.name }}; {% endif %} {% partial convertToV8 field %} diff --git a/generate/templates/partials/sync_function.cc b/generate/templates/partials/sync_function.cc index cf6febe67..9ace65b3b 100644 --- a/generate/templates/partials/sync_function.cc +++ b/generate/templates/partials/sync_function.cc @@ -18,7 +18,7 @@ NAN_METHOD({{ cppClassName }}::{{ cppFunctionName }}) { {%partial convertFromV8 arg %} {%if arg.saveArg %} v8::Local {{ arg.name }}(Nan::To(info[{{ arg.jsArg }}]).ToLocalChecked()); - {{ cppClassName }} *thisObj = Nan::ObjectWrap::Unwrap<{{ cppClassName }}>(info.This()); + {{ cppClassName }} *thisObj = Nan::ObjectWrap::Unwrap<{{ cppClassName }}>(info.Holder()); thisObj->{{ cppFunctionName }}_{{ arg.name }}.Reset({{ arg.name }}); {%endif%} @@ -28,7 +28,7 @@ NAN_METHOD({{ cppClassName }}::{{ cppFunctionName }}) { {%-- Inside a free call, if the value is already free'd don't do it again.--%} {%if cppFunctionName == "Free" %} - if (Nan::ObjectWrap::Unwrap<{{ cppClassName }}>(info.This())->GetValue() != NULL) { + if (Nan::ObjectWrap::Unwrap<{{ cppClassName }}>(info.Holder())->GetValue() != NULL) { {%endif%} git_error_clear(); @@ -41,7 +41,7 @@ NAN_METHOD({{ cppClassName }}::{{ cppFunctionName }}) { {%if not arg.isReturn%} , {%if arg.isSelf %} - Nan::ObjectWrap::Unwrap<{{ arg.cppClassName }}>(info.This())->GetValue() + Nan::ObjectWrap::Unwrap<{{ arg.cppClassName }}>(info.Holder())->GetValue() {%else%} from_{{ arg.name }} {%endif%} @@ -57,7 +57,7 @@ NAN_METHOD({{ cppClassName }}::{{ cppFunctionName }}) { {%if not arg.shouldAlloc %}&{%endif%} {%endif%} {%if arg.isSelf %} - Nan::ObjectWrap::Unwrap<{{ arg.cppClassName }}>(info.This())->GetValue() + Nan::ObjectWrap::Unwrap<{{ arg.cppClassName }}>(info.Holder())->GetValue() {%elsif arg.isReturn %} {{ arg.name }} {%else%} @@ -88,7 +88,7 @@ NAN_METHOD({{ cppClassName }}::{{ cppFunctionName }}) { {%endif%} {%if cppFunctionName == "Free" %} - Nan::ObjectWrap::Unwrap<{{ cppClassName }}>(info.This())->ClearValue(); + Nan::ObjectWrap::Unwrap<{{ cppClassName }}>(info.Holder())->ClearValue(); } // lock master scope end {%endif%} diff --git a/package-lock.json b/package-lock.json index cd61c7da1..7b7e2aba8 100644 --- a/package-lock.json +++ b/package-lock.json @@ -15,7 +15,7 @@ "got": "^14.4.7", "json5": "^2.1.0", "lodash": "^4.18.1", - "nan": "^2.23.1", + "nan": "axosoft/nan#v2.26.2-axosoft.0", "node-gyp": "^11.2.0", "tar-fs": "^3.0.9" }, @@ -3960,9 +3960,9 @@ "license": "MIT" }, "node_modules/nan": { - "version": "2.23.1", - "resolved": "https://registry.npmjs.org/nan/-/nan-2.23.1.tgz", - "integrity": "sha512-r7bBUGKzlqk8oPBDYxt6Z0aEdF1G1rwlMcLk8LCOMbOzf0mG+JUfUzG4fIMWwHWP0iyaLWEQZJmtB7nOHEm/qw==", + "name": "@axosoft/nan", + "version": "2.27.0", + "resolved": "git+ssh://git@github.com/axosoft/nan.git#af863d47852f18aabcd963ee806aa130d76cf925", "license": "MIT" }, "node_modules/negotiator": { @@ -8731,9 +8731,8 @@ "integrity": "sha512-6FlzubTLZG3J2a/NVCAleEhjzq5oxgHyaCU9yYXvcLsvoVaHJq/s5xXI6/XXP6tz7R9xAOtHnSO/tXtF3WRTlA==" }, "nan": { - "version": "2.23.1", - "resolved": "https://registry.npmjs.org/nan/-/nan-2.23.1.tgz", - "integrity": "sha512-r7bBUGKzlqk8oPBDYxt6Z0aEdF1G1rwlMcLk8LCOMbOzf0mG+JUfUzG4fIMWwHWP0iyaLWEQZJmtB7nOHEm/qw==" + "version": "git+ssh://git@github.com/axosoft/nan.git#af863d47852f18aabcd963ee806aa130d76cf925", + "from": "nan@axosoft/nan#v2.26.2-axosoft.0" }, "negotiator": { "version": "1.0.0", diff --git a/package.json b/package.json index 0309ab81e..b92ea9051 100644 --- a/package.json +++ b/package.json @@ -43,7 +43,7 @@ "got": "^14.4.7", "json5": "^2.1.0", "lodash": "^4.18.1", - "nan": "^2.23.1", + "nan": "axosoft/nan#v2.26.2-axosoft.0", "node-gyp": "^11.2.0", "tar-fs": "^3.0.9" }, From e6c71bc1ea47dc8ebc945bd8d707c0400bb46b08 Mon Sep 17 00:00:00 2001 From: John Alden Date: Wed, 22 Apr 2026 18:53:17 -0700 Subject: [PATCH 8/9] bump to 0.28.0-alpha.38 --- package-lock.json | 4 ++-- package.json | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/package-lock.json b/package-lock.json index 7b7e2aba8..f647b7866 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "nodegit", - "version": "0.28.0-alpha.37", + "version": "0.28.0-alpha.38", "lockfileVersion": 2, "requires": true, "packages": { "": { "name": "nodegit", - "version": "0.28.0-alpha.37", + "version": "0.28.0-alpha.38", "hasInstallScript": true, "license": "MIT", "dependencies": { diff --git a/package.json b/package.json index b92ea9051..6476a4a7a 100644 --- a/package.json +++ b/package.json @@ -1,7 +1,7 @@ { "name": "nodegit", "description": "Node.js libgit2 asynchronous native bindings", - "version": "0.28.0-alpha.37", + "version": "0.28.0-alpha.38", "homepage": "http://nodegit.org", "keywords": [ "libgit2", From bdcbe3973994841a62716062d187c14068579a54 Mon Sep 17 00:00:00 2001 From: Ian Hattendorf Date: Thu, 16 Jul 2026 11:47:07 -0700 Subject: [PATCH 9/9] Update maintainers --- README.md | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 72442d791..da8e302e6 100644 --- a/README.md +++ b/README.md @@ -11,10 +11,13 @@ Visit [slack.libgit2.org](http://slack.libgit2.org/) to sign up, then join us in #nodegit. ## Maintained by ## -Tyler Ang-Wanek [@twwanek](http://twitter.com/twwanek) with help from tons of +Alex Aveillán [@AlexaXs](http://github.com/AlexaXs) with help from tons of [awesome contributors](https://github.com/nodegit/nodegit/contributors)! ### Alumni Maintainers ### +Ian Hattendorf [@ianhattendorf](http://github.com/ianhattendorf), +John Alden [@zawata](http://github.com/zawata), +Tyler Ang-Wanek [@twwanek](http://twitter.com/twwanek), Tim Branyen [@tbranyen](http://twitter.com/tbranyen), John Haley [@johnhaley81](http://twitter.com/johnhaley81), Max Korp [@maxkorp](http://twitter.com/MaximilianoKorp),