open-swe/ui/package.json
Adam Moussa 2a226e2cd1
Some checks failed
CI / Lint (push) Has been cancelled
CI / Format check (push) Has been cancelled
CI / Unit tests (push) Has been cancelled
CI / Playwright E2E (push) Has been cancelled
CI / Docker build smoke (push) Has been cancelled
fix(ui): pin nitro to patched 3.0.260603-beta (#116)
Resolves Dependabot GHSA-9phm-9p8f-hw5m (open redirect via
protocol-relative URL in wildcard route rules) and GHSA-5w89-w975-hf9q
(proxy scope bypass via percent-encoded path traversal in routeRules).

nitro was pinned to "latest", which Dependabot can't resolve to a fixed
version, so the alerts stayed open even though the lockfile already
resolved 3.0.260603-beta (newer than the 3.0.260429-beta patch line).
Pin it to an exact version — nitro ships a date-stamped beta channel
where caret ranges behave unpredictably — so installs are reproducible
and both alerts close.

bun.lock also reconciles @pierre/trees beta.4 -> beta.5, which the
manifest already declared but the committed lockfile was stale on.
2026-07-02 18:41:14 -04:00

69 lines
No EOL
2.1 KiB
JSON

{
"name": "open-swe-dashboard",
"private": true,
"type": "module",
"scripts": {
"dev": "vite dev --port 3000",
"build": "vite build",
"preview": "vite preview",
"test": "vitest run",
"lint": "eslint",
"format": "prettier --write \"**/*.{ts,tsx,js,jsx}\"",
"typecheck": "tsc --noEmit"
},
"dependencies": {
"@base-ui/react": "^1.4.1",
"@fontsource-variable/inter": "^5.2.8",
"@langchain/core": "^1.1.48",
"@langchain/langgraph-sdk": "^1.9.21",
"@langchain/react": "^1.0.22",
"@monaco-editor/react": "^4.7.0",
"@phosphor-icons/react": "^2.1.10",
"@pierre/diffs": "^1.2.1",
"@pierre/trees": "1.0.0-beta.5",
"@tailwindcss/vite": "^4.2.1",
"@tanstack/react-devtools": "^0.10.0",
"@tanstack/react-query": "^5.100.10",
"@tanstack/react-query-devtools": "^5.100.10",
"@tanstack/react-router": "^1.167.4",
"@tanstack/react-router-devtools": "^1.166.9",
"@tanstack/react-router-ssr-query": "^1.166.9",
"@tanstack/react-start": "^1.166.15",
"@tanstack/router-plugin": "^1.166.13",
"class-variance-authority": "^0.7.1",
"clsx": "^2.1.1",
"lucide-react": "^1.16.0",
"monaco-editor": "^0.55.1",
"nitro": "3.0.260603-beta",
"react": "^19.2.4",
"react-dom": "^19.2.4",
"react-icons": "^5.6.0",
"shadcn": "^4.7.0",
"shiki": "^4.1.0",
"streamdown": "^2.5.0",
"tailwind-merge": "^3.6.0",
"tailwindcss": "^4.2.1",
"tw-animate-css": "^1.4.0",
"vite-tsconfig-paths": "^5.1.4"
},
"devDependencies": {
"@tanstack/devtools-vite": "^0.8.1",
"@tanstack/eslint-config": "^0.4.0",
"@testing-library/dom": "^10.4.1",
"@testing-library/react": "^16.3.2",
"@types/node": "^24.0.0",
"@types/react": "^19.2.14",
"@types/react-dom": "^19.2.3",
"@vitejs/plugin-react": "^6.0.3",
"jsdom": "^27.4.0",
"prettier": "^3.8.1",
"prettier-plugin-tailwindcss": "^0.8.0",
"typescript": "^6.0.3",
"vite": "^8.1.2",
"vite-plugin-pwa": "^1.3.0",
"vitest": "^4.1.0",
"web-vitals": "^5.1.0",
"workbox-build": "^7.4.1",
"workbox-window": "^7.4.1"
}
}