Files
rfc-app/frontend/package.json
T
Ben Stull cdbc8078b6 Patch 0.31.5: pin transitive security floors (tqdm, idna)
backend/requirements.txt carries only loose `>=` direct constraints and
no compiled lockfile, so osv-scanner v2 resolves the transitive graph and
pins each unpinned transitive package to its MINIMUM published version —
surfacing CVEs in ancient releases pip would never install. That fired a
phantom HIGH (tqdm 4.9.0, GHSA-r7q7-xcjw-qx8q) plus an idna finding on the
OHM Patchwatch radar, even though the live deployment runs patched versions.

Add `tqdm>=4.66.3` and `idna>=3.15` to anchor the resolver to the patched
range. osv-scanner now reports zero findings. No direct-import / schema /
API / config change; deployed installs already satisfy the floors.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-03 07:56:14 -07:00

36 lines
905 B
JSON

{
"name": "rfc-app-frontend",
"private": true,
"version": "0.31.5",
"type": "module",
"scripts": {
"dev": "vite",
"build": "vite build",
"preview": "vite preview"
},
"dependencies": {
"@amplitude/unified": "^1.1.9",
"@codemirror/commands": "^6.10.3",
"@codemirror/lang-markdown": "^6.5.0",
"@codemirror/language": "^6.12.3",
"@codemirror/state": "^6.6.0",
"@codemirror/view": "^6.43.0",
"@tiptap/extension-placeholder": "^3.5.0",
"@tiptap/pm": "^3.5.0",
"@tiptap/react": "^3.5.0",
"@tiptap/starter-kit": "^3.5.0",
"dompurify": "^3.2.4",
"marked": "^18.0.4",
"mermaid": "^11.15.0",
"react": "^19.2.6",
"react-dom": "^19.2.6",
"react-router-dom": "^7.2.0"
},
"devDependencies": {
"@types/react": "^19.2.14",
"@types/react-dom": "^19.2.3",
"@vitejs/plugin-react": "^6.0.1",
"vite": "^8.0.12"
}
}