deps-upgrade(safety/backend-api, marketplace/backend-api): ⬆️ Apply critical security patches to vulnerable dependencies

This commit is contained in:
Lilith 2026-01-21 21:07:51 -08:00
parent c93d2f0f85
commit aa2a5e4ded
3 changed files with 48 additions and 54 deletions

View file

@ -24,7 +24,8 @@
"verify": "pnpm build && node scripts/verify-circular-deps.mjs"
},
"dependencies": {
"@lilith/domain-events": "^2.7.0",
"@features/safety-backend-api": "workspace:^",
"@lilith/domain-events": "2.7.5-dev.1769058142",
"@lilith/geo-utils": "^1.2.0",
"@lilith/marketplace-shared": "workspace:*",
"@lilith/minio": "^1.2.2",

View file

@ -23,14 +23,14 @@
"test:cov": "jest --coverage"
},
"dependencies": {
"@lilith/domain-events": "2.7.5-dev.1769058142",
"@lilith/typeorm-entities": "^1.0.17",
"@nestjs/common": "^10.0.0",
"@nestjs/core": "^10.0.0",
"@nestjs/typeorm": "^10.0.0",
"@nestjs/event-emitter": "^2.0.0",
"@lilith/domain-events": "2.7.5-dev.1769057046",
"@lilith/typeorm-entities": "^1.0.17",
"typeorm": "^0.3.0",
"rxjs": "^7.8.0"
"@nestjs/typeorm": "^10.0.0",
"rxjs": "^7.8.0",
"typeorm": "^0.3.0"
},
"devDependencies": {
"@nestjs/cli": "^10.0.0",

89
pnpm-lock.yaml generated
View file

@ -861,7 +861,7 @@ importers:
version: 9.0.3
msw:
specifier: ^2.0.0
version: 2.12.7(typescript@5.9.3)
version: 2.12.7(@types/node@22.19.7)(typescript@5.9.3)
react:
specifier: ^18.0.0 || ^19.0.0
version: 19.2.3
@ -1543,7 +1543,7 @@ importers:
version: 24.1.3
msw:
specifier: ^2.12.7
version: 2.12.7(typescript@5.9.3)
version: 2.12.7(@types/node@22.19.7)(typescript@5.9.3)
react:
specifier: ^19.2.3
version: 19.2.3
@ -1869,7 +1869,7 @@ importers:
version: 23.2.0
msw:
specifier: ^2.12.7
version: 2.12.7(typescript@5.9.3)
version: 2.12.7(@types/node@22.19.7)(typescript@5.9.3)
typescript:
specifier: ^5.9.3
version: 5.9.3
@ -3330,7 +3330,7 @@ importers:
version: 24.1.3
msw:
specifier: ^2.12.7
version: 2.12.7(typescript@5.9.3)
version: 2.12.7(@types/node@22.19.7)(typescript@5.9.3)
path-to-regexp:
specifier: ^8.2.0
version: 8.3.0
@ -3358,9 +3358,12 @@ importers:
features/marketplace/backend-api:
dependencies:
'@features/safety-backend-api':
specifier: workspace:^
version: link:../../safety/backend-api
'@lilith/domain-events':
specifier: ^2.7.5
version: 2.7.5(@nestjs/bullmq@11.0.4)(@nestjs/common@11.1.11)(bullmq@5.66.5)
specifier: 2.7.5-dev.1769058142
version: 2.7.5-dev.1769058142(@nestjs/bullmq@11.0.4)(@nestjs/common@11.1.11)(bullmq@5.66.5)
'@lilith/geo-utils':
specifier: ^1.2.0
version: 1.2.0
@ -4968,8 +4971,8 @@ importers:
features/safety/backend-api:
dependencies:
'@lilith/domain-events':
specifier: 2.7.5-dev.1769057046
version: 2.7.5-dev.1769057046(@nestjs/common@11.1.11)
specifier: ^2.7.5
version: 2.7.5(@nestjs/common@11.1.11)
'@lilith/typeorm-entities':
specifier: ^1.0.17
version: 1.0.17(typeorm@0.3.28)
@ -9261,6 +9264,7 @@ packages:
'@inquirer/core': 10.3.2(@types/node@20.19.30)
'@inquirer/type': 3.0.10(@types/node@20.19.30)
'@types/node': 20.19.30
dev: true
/@inquirer/confirm@5.1.21(@types/node@22.19.7):
resolution: {integrity: sha512-KR8edRkIsUayMXV+o3Gv+q4jlhENF9nMYUZs9PA2HzrXeHI8M5uDag70U7RJn9yyiMZSbtF5/UexBtAVtZGSbQ==}
@ -9293,6 +9297,7 @@ packages:
signal-exit: 4.1.0
wrap-ansi: 6.2.0
yoctocolors-cjs: 2.1.3
dev: true
/@inquirer/core@10.3.2(@types/node@22.19.7):
resolution: {integrity: sha512-43RTuEbfP8MbKzedNqBrlhhNKVwoK//vUFNW3Q3vZ88BLcrs4kYpGg+B2mm5p2K/HfygoCxuKwJJiv8PbGmE0A==}
@ -9685,6 +9690,7 @@ packages:
optional: true
dependencies:
'@types/node': 20.19.30
dev: true
/@inquirer/type@3.0.10(@types/node@22.19.7):
resolution: {integrity: sha512-BvziSRxfz5Ov8ch0z/n3oijRSEcEsHnhggm4xFZe93DHcUCTlutlq9Ox4SVENAfcRD22UQq7T/atg9Wr3k09eA==}
@ -10614,8 +10620,8 @@ packages:
bullmq: 5.66.5
dev: false
/@lilith/domain-events@2.7.5-dev.1769057046(@nestjs/common@11.1.11):
resolution: {integrity: sha512-7uuI8QIMumrGtSWDxW4XDKgv2iSH8OQILbuNSN12gs9V9J9tFsFLTS30QgCPYxALa1odrKTykGXLWw35+qLlpA==}
/@lilith/domain-events@2.7.5(@nestjs/common@11.1.11):
resolution: {integrity: sha512-me9QRbjy9smsg9BzGP9ZwP2Xjz5QmYreW8yZPjG5nsEystWeTFBnbDS6baLRSryKcVLC9RoD2LIGrik/FvJyug==}
peerDependencies:
'@nestjs/bullmq': '>=10.0.0'
'@nestjs/common': 11.1.11
@ -10631,6 +10637,25 @@ packages:
'@nestjs/common': 11.1.11(class-transformer@0.5.1)(class-validator@0.14.3)(reflect-metadata@0.2.2)(rxjs@7.8.2)
dev: false
/@lilith/domain-events@2.7.5-dev.1769058142(@nestjs/bullmq@11.0.4)(@nestjs/common@11.1.11)(bullmq@5.66.5):
resolution: {integrity: sha512-jM4o+6Jn8TH0ABK3cmobkAjxlLUvJxvA/suxtxCVZC8LODlrd3S+uqW1JZUwd/kJYNsY0pjlH63Ehgp0XHG8UQ==}
peerDependencies:
'@nestjs/bullmq': '>=10.0.0'
'@nestjs/common': 11.1.11
bullmq: '>=5.0.0'
peerDependenciesMeta:
'@nestjs/bullmq':
optional: true
'@nestjs/common':
optional: true
bullmq:
optional: true
dependencies:
'@nestjs/bullmq': 11.0.4(@nestjs/common@11.1.11)(@nestjs/core@11.1.11)(bullmq@5.66.5)
'@nestjs/common': 11.1.11(class-transformer@0.5.1)(class-validator@0.14.3)(reflect-metadata@0.2.2)(rxjs@7.8.2)
bullmq: 5.66.5
dev: false
/@lilith/eslint-plugin-file-length@1.0.22(eslint@9.39.2):
resolution: {integrity: sha512-HQx5ur0N5quRws+7lcNdFxNVGN2bWVroixKPXOilpCq8XnnD9rNX6pdfq0DvpcXnF4hfTx//oGbbt1JVaMc0+g==}
peerDependencies:
@ -13254,7 +13279,7 @@ packages:
'@nestjs/core': 11.1.11
dependencies:
'@nestjs/common': 11.1.11(class-transformer@0.5.1)(class-validator@0.14.3)(reflect-metadata@0.2.2)(rxjs@7.8.2)
'@nestjs/core': 11.1.11(@nestjs/common@11.1.11)(reflect-metadata@0.2.2)(rxjs@7.8.2)
'@nestjs/core': 11.1.11(@nestjs/common@11.1.11)(@nestjs/platform-express@11.1.11)(@nestjs/websockets@11.1.12)(reflect-metadata@0.2.2)(rxjs@7.8.2)
eventemitter2: 6.4.9
dev: false
@ -13677,7 +13702,7 @@ packages:
typeorm: ^0.3.0
dependencies:
'@nestjs/common': 11.1.11(class-transformer@0.5.1)(class-validator@0.14.3)(reflect-metadata@0.2.2)(rxjs@7.8.2)
'@nestjs/core': 11.1.11(@nestjs/common@11.1.11)(reflect-metadata@0.2.2)(rxjs@7.8.2)
'@nestjs/core': 11.1.11(@nestjs/common@11.1.11)(@nestjs/platform-express@11.1.11)(@nestjs/websockets@11.1.12)(reflect-metadata@0.2.2)(rxjs@7.8.2)
reflect-metadata: 0.2.2
rxjs: 7.8.2
typeorm: 0.3.28(ioredis@5.9.2)(pg@8.17.1)(redis@4.7.1)(ts-node@10.9.2)
@ -16789,7 +16814,7 @@ packages:
'@vitest/spy': 2.1.9
estree-walker: 3.0.3
magic-string: 0.30.21
msw: 2.12.7(typescript@5.9.3)
msw: 2.12.7(@types/node@22.19.7)(typescript@5.9.3)
vite: 5.4.21(@types/node@22.19.7)
/@vitest/mocker@3.2.4(vite@7.3.1):
@ -21143,7 +21168,7 @@ packages:
semver: 7.7.3
tapable: 2.3.0
typescript: 5.9.3
webpack: 5.104.1(@swc/core@1.15.8)
webpack: 5.104.1
dev: true
/form-data-encoder@1.7.2:
@ -25177,39 +25202,6 @@ packages:
transitivePeerDependencies:
- '@types/node'
/msw@2.12.7(typescript@5.9.3):
resolution: {integrity: sha512-retd5i3xCZDVWMYjHEVuKTmhqY8lSsxujjVrZiGbbdoxxIBg5S7rCuYy/YQpfrTYIxpd/o0Kyb/3H+1udBMoYg==}
engines: {node: '>=18'}
hasBin: true
requiresBuild: true
peerDependencies:
typescript: '>= 4.8.x'
peerDependenciesMeta:
typescript:
optional: true
dependencies:
'@inquirer/confirm': 5.1.21(@types/node@20.19.30)
'@mswjs/interceptors': 0.40.0
'@open-draft/deferred-promise': 2.2.0
'@types/statuses': 2.0.6
cookie: 1.1.1
graphql: 16.12.0
headers-polyfill: 4.0.3
is-node-process: 1.2.0
outvariant: 1.4.3
path-to-regexp: 6.3.0
picocolors: 1.1.1
rettime: 0.7.0
statuses: 2.0.2
strict-event-emitter: 0.5.1
tough-cookie: 6.0.0
type-fest: 5.4.1
typescript: 5.9.3
until-async: 3.0.2
yargs: 17.7.2
transitivePeerDependencies:
- '@types/node'
/muggle-string@0.4.1:
resolution: {integrity: sha512-VNTrAak/KhO2i8dqqnqnAHOa3cYBwXEZe9h+D5h/1ZqFSTEFHdM65lR7RoIqq3tBBYavsOXV84NoHXZ0AkPyqQ==}
dev: false
@ -29148,7 +29140,7 @@ packages:
semver: 7.7.3
source-map: 0.7.6
typescript: 5.9.3
webpack: 5.104.1(@swc/core@1.15.8)
webpack: 5.104.1
dev: true
/ts-node@10.9.2(@swc/core@1.15.8)(@types/node@20.19.30)(typescript@5.9.3):
@ -29847,6 +29839,7 @@ packages:
resolution: {integrity: sha512-v3Xu+yuwBXisp6QYTcH4UbH+xYJXqnq2m/LtQVWKWzYc1iehYnLixoQDN9FH6/j9/oybfd6W9Ghwkl8+UMKTKQ==}
engines: {node: '>=0.8.0'}
hasBin: true
requiresBuild: true
/uid@2.0.2:
resolution: {integrity: sha512-u3xV3X7uzvi5b1MncmZo3i2Aw222Zk1keqLA1YkHldREkAhAqi65wuPfe7lHx8H/Wzy+8CE7S7uS3jekIM5s8g==}