mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 11:33:14 +00:00
Resolves Dependabot GHSA-9phm-9p8f-hw5m (open redirect via protocol-relative URL in wildcard route rules) and GHSA-5w89-w975-hf9q (proxy scope bypass via percent-encoded path traversal in routeRules). nitro was pinned to "latest", which Dependabot can't resolve to a fixed version, so the alerts stayed open even though the lockfile already resolved 3.0.260603-beta (newer than the 3.0.260429-beta patch line). Pin it to an exact version — nitro ships a date-stamped beta channel where caret ranges behave unpredictably — so installs are reproducible and both alerts close. bun.lock also reconciles @pierre/trees beta.4 -> beta.5, which the manifest already declared but the committed lockfile was stale on. |
||
|---|---|---|
| .. | ||
| assets | ||
| public | ||
| src | ||
| .cta.json | ||
| .gitignore | ||
| .prettierignore | ||
| .prettierrc | ||
| bun.lock | ||
| components.json | ||
| eslint.config.js | ||
| package.json | ||
| pnpm-workspace.yaml | ||
| README.md | ||
| tsconfig.json | ||
| vercel.json | ||
| vite.config.ts | ||
TanStack Start + shadcn/ui
This is a template for a new TanStack Start project with React, TypeScript, and shadcn/ui.
Adding components
To add components to your app, run the following command:
npx shadcn@latest add button
This will place the ui components in the components directory.
Using components
To use the components in your app, import them as follows:
import { Button } from "@/components/ui/button";