diff --git a/package.json b/package.json index 1d3e5f3..2c8509c 100644 --- a/package.json +++ b/package.json @@ -44,7 +44,9 @@ }, "pnpm": { "overrides": { - "nanoid@>=3.0.0 <4.0.0": "3.3.18" + "brace-expansion@>=5.0.0 <6.0.0": "5.0.12", + "nanoid@>=3.0.0 <4.0.0": "3.3.18", + "undici@^5.28.4": "6.29.0" } } } diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index ef17351..a1d2211 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -5,7 +5,9 @@ settings: excludeLinksFromLockfile: false overrides: + brace-expansion@>=5.0.0 <6.0.0: 5.0.12 nanoid@>=3.0.0 <4.0.0: 3.3.18 + undici@^5.28.4: 6.29.0 importers: @@ -483,10 +485,6 @@ packages: cpu: [x64] os: [win32] - '@fastify/busboy@2.1.1': - resolution: {integrity: sha512-vBZP4NlzfOlerQTnba4aqZoMhE/a9HY7HRqoOPaETQcSQuWEIyZMHGfVu6w9wGtGK5fED5qRs2DteVCjOH60sA==} - engines: {node: '>=14'} - '@jridgewell/resolve-uri@3.1.2': resolution: {integrity: sha512-bRISgCIjP20/tbWSPWMEi54QVPRZExkuD9lJL+UIxUKtwVJA8wW1Trb1jMs1RFXo1CBTNZ/5hpC9QvmKWdopKw==} engines: {node: '>=6.0.0'} @@ -957,8 +955,8 @@ packages: resolution: {integrity: sha512-BLrgEcRTwX2o6gGxGOCNyMvGSp35YofuYzw9h1IMTRmKqttAZZVU67bdb9Pr2vUHA8+j3i2tJfjO6C6+4myGTA==} engines: {node: 18 || 20 || >=22} - brace-expansion@5.0.9: - resolution: {integrity: sha512-ScQ4IuvIEF1TMlP7Zt+vjJ//9zlPb2SDcxWxM3bk8s6t6GGdJ7KO1dCcTidOPJKePW30LE/2cT7wCyPho9/Wxg==} + brace-expansion@5.0.12: + resolution: {integrity: sha512-YovQ3rzhaLMIrDjNDMkNS01tea93qhEhG5xy8f6+R0l+dw3Ki+5sCoIoI942iuLZTHWogWktgwVDhU09iNEimQ==} engines: {node: 20 || >=22} capnp-ts@0.7.0: @@ -1495,9 +1493,9 @@ packages: resolution: {integrity: sha512-b7zoBQvpWp0vuN5q2vK2RRBR2SvuruQAs50DApdDveBSn3eSYd84IaHodFqQIMlvY9K2VnyBUEXgwOBuGU9GBg==} engines: {node: '>=14'} - undici@5.29.0: - resolution: {integrity: sha512-raqeBD6NQK4SkWhQzeYKd1KmIG6dllBOTt55Rmkt4HtI9mwdWtJljnrXjAFUBLTSN67HWrOIZ3EPF4kjUw80Bg==} - engines: {node: '>=14.0'} + undici@6.29.0: + resolution: {integrity: sha512-R+RODBqp6i2pPflGdq+xIOUkl+RNfGgHwoinecKu/JCuf2uO06cOKoDbI2P7Dn6KcswdKwrczbU6IYJ6K8X+wg==} + engines: {node: '>=18.17'} unenv@2.0.0-rc.0: resolution: {integrity: sha512-H0kl2w8jFL/FAk0xvjVing4bS3jd//mbg1QChDnn58l9Sc5RtduaKmLAL8n+eBw5jJo8ZjYV7CrEGage5LAOZQ==} @@ -1895,8 +1893,6 @@ snapshots: '@esbuild/win32-x64@0.28.1': optional: true - '@fastify/busboy@2.1.1': {} - '@jridgewell/resolve-uri@3.1.2': {} '@jridgewell/sourcemap-codec@1.5.5': {} @@ -2210,7 +2206,7 @@ snapshots: balanced-match@4.0.4: {} - brace-expansion@5.0.9: + brace-expansion@5.0.12: dependencies: balanced-match: 4.0.4 @@ -2527,7 +2523,7 @@ snapshots: exit-hook: 2.2.1 glob-to-regexp: 0.4.1 stoppable: 1.1.0 - undici: 5.29.0 + undici: 6.29.0 workerd: 1.20240718.0 ws: 8.21.1 youch: 3.3.4 @@ -2539,7 +2535,7 @@ snapshots: minimatch@10.2.6: dependencies: - brace-expansion: 5.0.9 + brace-expansion: 5.0.12 minipass@7.1.3: {} @@ -2802,9 +2798,7 @@ snapshots: unbash@4.0.10: {} - undici@5.29.0: - dependencies: - '@fastify/busboy': 2.1.1 + undici@6.29.0: {} unenv@2.0.0-rc.0: dependencies: diff --git a/scripts/check-code-health.mjs b/scripts/check-code-health.mjs index 45f55b6..04dc8eb 100644 --- a/scripts/check-code-health.mjs +++ b/scripts/check-code-health.mjs @@ -220,33 +220,14 @@ function checkDependencies() { const severe = Object.entries(report.advisories ?? {}).filter( ([, advisory]) => ["critical", "high"].includes(advisory.severity) ); - const allowedHigh = new Set(["1114638", "1114640", "1121245"]); - const unexpected = severe.filter(([id]) => !allowedHigh.has(id)); - const missing = [...allowedHigh].filter( - (id) => !severe.some(([observedId]) => observedId === id) - ); - const reviewDate = new Date("2026-09-12T00:00:00Z"); - log( - `Dependencies: ${severe.length} critical/high advisories; ` + - `${severe.length - unexpected.length} accepted PartyKit/Miniflare findings.` - ); - if (Date.now() >= reviewDate.getTime()) { - throw new Error( - "PartyKit dependency-risk exception expired on 2026-09-12 (#26)." - ); - } - if (unexpected.length > 0) { + log(`Dependencies: ${severe.length} critical/high advisories.`); + if (severe.length > 0) { throw new Error( - `Unexpected critical/high advisories: ${unexpected + `Critical/high advisories: ${severe .map(([id, advisory]) => `${id}/${advisory.github_advisory_id}`) .join(", ")}` ); } - if (missing.length > 0) { - log( - `Dependency risk improved; remove resolved exceptions: ${missing.join(", ")}.` - ); - } } function countMatches(pattern) {