From 2a226e2cd16bc99684efe079041bf440442f2f50 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Thu, 2 Jul 2026 18:41:14 -0400 Subject: [PATCH] fix(ui): pin nitro to patched 3.0.260603-beta (#116) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Resolves Dependabot GHSA-9phm-9p8f-hw5m (open redirect via protocol-relative URL in wildcard route rules) and GHSA-5w89-w975-hf9q (proxy scope bypass via percent-encoded path traversal in routeRules). nitro was pinned to "latest", which Dependabot can't resolve to a fixed version, so the alerts stayed open even though the lockfile already resolved 3.0.260603-beta (newer than the 3.0.260429-beta patch line). Pin it to an exact version — nitro ships a date-stamped beta channel where caret ranges behave unpredictably — so installs are reproducible and both alerts close. bun.lock also reconciles @pierre/trees beta.4 -> beta.5, which the manifest already declared but the committed lockfile was stale on. --- ui/bun.lock | 8 +++++--- ui/package.json | 2 +- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/ui/bun.lock b/ui/bun.lock index 9889a194..dfdc22c6 100644 --- a/ui/bun.lock +++ b/ui/bun.lock @@ -13,7 +13,7 @@ "@monaco-editor/react": "^4.7.0", "@phosphor-icons/react": "^2.1.10", "@pierre/diffs": "^1.2.1", - "@pierre/trees": "1.0.0-beta.4", + "@pierre/trees": "1.0.0-beta.5", "@tailwindcss/vite": "^4.2.1", "@tanstack/react-devtools": "^0.10.0", "@tanstack/react-query": "^5.100.10", @@ -27,7 +27,7 @@ "clsx": "^2.1.1", "lucide-react": "^1.16.0", "monaco-editor": "^0.55.1", - "nitro": "latest", + "nitro": "3.0.260603-beta", "react": "^19.2.4", "react-dom": "^19.2.4", "react-icons": "^5.6.0", @@ -494,7 +494,9 @@ "@pierre/theme": ["@pierre/theme@1.0.3", "", {}, "sha512-sWHv11TMoqKxKDgTIk5VbhQjdPhs8DCcBxbjh3mRlS3YOM/OcrWoGX6MM8eBGn9cUu3M46Py0JnxsG2nJaFTuA=="], - "@pierre/trees": ["@pierre/trees@1.0.0-beta.4", "", { "dependencies": { "preact": "11.0.0-beta.0", "preact-render-to-string": "6.6.5" }, "peerDependencies": { "react": "^18.3.1 || ^19.0.0", "react-dom": "^18.3.1 || ^19.0.0" } }, "sha512-OfT1yk9ne8Te5+GB5zUY8yqE6B8BqjBHQJleH4lu8ltwNpoocZl4vXt1AzlEExpxI/pp+AFX5QG+lR3JjtTEag=="], + "@pierre/theming": ["@pierre/theming@0.0.2", "", { "peerDependencies": { "@pierre/theme": "^1.1.0", "@shikijs/themes": "^3.0.0 || ^4.0.0", "react": "^18.3.1 || ^19.0.0", "react-dom": "^18.3.1 || ^19.0.0", "shiki": "^3.0.0 || ^4.0.0" }, "optionalPeers": ["@pierre/theme", "@shikijs/themes", "react", "react-dom", "shiki"] }, "sha512-QM1M4stXfnzfaE8I8YbjXSApV8c+2dBsXJj8eYg9WTpBR/cTmCZIcfGnN4p13iRrYu2Br/R/OJfEL7uR8Qjctw=="], + + "@pierre/trees": ["@pierre/trees@1.0.0-beta.5", "", { "dependencies": { "@pierre/theming": "0.0.2", "preact": "11.0.0-beta.0", "preact-render-to-string": "6.6.5" }, "peerDependencies": { "react": "^18.3.1 || ^19.0.0", "react-dom": "^18.3.1 || ^19.0.0" } }, "sha512-IzxkB9qv6GLbeEXObhlAD205LfYHiLeRwJdnaIdX0f5keTZF4X9EfiuEQ3QiyxOxouVVmUX3rX7m6a8zNMo/wA=="], "@rolldown/binding-android-arm64": ["@rolldown/binding-android-arm64@1.1.4", "", { "os": "android", "cpu": "arm64" }, "sha512-EZLpf/8y7GXkkra90ML47kzik/GMP3EMcE9bPyHmRfxLC6z9+aW5A8poCsoxjrT5GfEcNAAvWwUHjvP1pUQkfw=="], diff --git a/ui/package.json b/ui/package.json index dcce9699..35c2217f 100644 --- a/ui/package.json +++ b/ui/package.json @@ -34,7 +34,7 @@ "clsx": "^2.1.1", "lucide-react": "^1.16.0", "monaco-editor": "^0.55.1", - "nitro": "latest", + "nitro": "3.0.260603-beta", "react": "^19.2.4", "react-dom": "^19.2.4", "react-icons": "^5.6.0",