Commit 9641e29
committed
fix(security): address Dependabot vulnerabilities
- Upgrade lodash 4.17.21 → 4.17.23 (fixes prototype pollution in _.unset/_.omit)
- Upgrade diff 8.0.2 → 8.0.3 (fixes DoS in parsePatch/applyPatch)
- Upgrade ai 5.0.0 → 5.0.52 (fixes file type whitelist bypass)
- Add @ai-sdk/provider and @ai-sdk/provider-utils overrides to fix version conflicts
Closes 11 Dependabot alerts (4 medium lodash, 4 low diff, 3 low ai)1 parent c9e4927 commit 9641e29
4 files changed
+34
-32
lines changedSome generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
29 | | - | |
| 29 | + | |
30 | 30 | | |
31 | | - | |
| 31 | + | |
32 | 32 | | |
33 | 33 | | |
34 | 34 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
43 | 43 | | |
44 | 44 | | |
45 | 45 | | |
46 | | - | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
47 | 49 | | |
48 | 50 | | |
49 | 51 | | |
| |||
59 | 61 | | |
60 | 62 | | |
61 | 63 | | |
62 | | - | |
| 64 | + | |
63 | 65 | | |
64 | 66 | | |
65 | 67 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
61 | 61 | | |
62 | 62 | | |
63 | 63 | | |
64 | | - | |
65 | | - | |
| 64 | + | |
| 65 | + | |
66 | 66 | | |
67 | 67 | | |
68 | 68 | | |
| |||
0 commit comments