headroom/docs/package.json

Ignoring revisions in .git-blame-ignore-revs. Click here to bypass and see the normal blame view.

48 lines
1.1 KiB
JSON
Raw Normal View History

2026-04-12 13:15:58 +06:00
{
"name": "headroom-docs",
"version": "0.0.0",
"private": true,
"scripts": {
"build": "next build",
"dev": "next dev",
"start": "next start",
"types:check": "fumadocs-mdx && next typegen && tsc --noEmit",
"postinstall": "fumadocs-mdx"
},
"dependencies": {
docs(ci): add CI/CD flow diagrams (#1062) ## Description Adds a visual CI/CD flow reference for Headroom so contributors can quickly understand the gated PR, release, Docker, docs deploy, fork approval, and manual validation paths. Also updates the release documentation to match the current release-please release flow instead of the stale push-to-main release model. ## Type of Change - [ ] Bug fix (non-breaking change that fixes an issue) - [ ] New feature (non-breaking change that adds functionality) - [ ] Breaking change (fix or feature that would cause existing functionality to change) - [x] Documentation update - [ ] Performance improvement - [ ] Code refactoring (no functional changes) ## Changes Made - Added `docs/content/docs/ci-cd-flows.mdx` with Mermaid diagrams and decision trees for PR review, release publishing, Docker publishing, docs deploys, fork workflow approval, and manual validation. - Updated `docs/content/docs/releases.mdx` to describe the current `release-please` -> GitHub Release -> `release.yml` publishing path. - Added the CI/CD flow page and existing release page to docs navigation. - Added Mermaid to the docs code highlighter language list. - Restored missing docs helper modules and aligned Fumadocs dependencies so the docs app can install, generate sources, type-check, and build. ## Testing - [ ] Unit tests pass (`pytest`) - [ ] Linting passes (`ruff check .`) - [ ] Type checking passes (`mypy headroom`) - [ ] New tests added for new functionality - [x] Manual testing performed ### Test Output ```text $ npm ci > headroom-docs@0.0.0 postinstall > fumadocs-mdx [MDX] generated files added 365 packages, and audited 367 packages $ npm run types:check > fumadocs-mdx && next typegen && tsc --noEmit [MDX] generated files Generating route types... ✓ Types generated successfully $ npm run build > next build ✓ Compiled successfully Running TypeScript ... Generating static pages ... ✓ Generating static pages (122/122) Note: next build completed successfully and emitted two existing Recharts container-size warnings during static generation. $ git diff --check # no output $ act workflow_dispatch -W .github/workflows/docs.yml -n *DRYRUN* [Deploy Documentation/deploy] 🏁 Job succeeded ``` ## Real Behavior Proof - Environment: Windows local checkout, branch `docs-ci-flow`, Node.js v22.22.0, `act` 0.2.87. - Exact command / steps: Ran `npm ci`, `npm run types:check`, and `npm run build` from `docs/`; ran `git diff --check` and `act workflow_dispatch -W .github/workflows/docs.yml -n` from the repository root. - Observed result: Docs dependencies install, Fumadocs source generation includes `ci-cd-flows.mdx`, TypeScript passes, Next production build completes, whitespace check passes, and the docs workflow dry-run succeeds under `act`. - Not tested: Full live GitHub Pages deploy and registry/release publishing, because this PR only changes docs and docs build wiring. ## Review Readiness - [x] I have performed a self-review - [x] This PR is ready for human review ## Checklist - [x] My code follows the project's style guidelines - [x] I have performed a self-review of my code - [x] I have commented my code, particularly in hard-to-understand areas - [x] I have made corresponding changes to the documentation - [ ] My changes generate no new warnings - [ ] I have added tests that prove my fix is effective or that my feature works - [ ] New and existing unit tests pass locally with my changes - [ ] I have updated the CHANGELOG.md if applicable ## Screenshots (if applicable) N/A. This is documentation and build wiring; the diagrams are Mermaid source blocks in the docs page. ## Additional Notes - No issue is linked because this PR was not opened for a specific tracked issue. - `npm run build` still reports two pre-existing Recharts container-size warnings while completing successfully. - Python unit/lint/type checks and changelog updates are not applicable to this docs-only change.
2026-06-17 01:05:15 -05:00
"@radix-ui/react-slot": "1.3.0",
"class-variance-authority": "0.7.1",
"clsx": "2.1.1",
2026-04-12 13:15:58 +06:00
"dotted-map": "^3.1.0",
docs(ci): add CI/CD flow diagrams (#1062) ## Description Adds a visual CI/CD flow reference for Headroom so contributors can quickly understand the gated PR, release, Docker, docs deploy, fork approval, and manual validation paths. Also updates the release documentation to match the current release-please release flow instead of the stale push-to-main release model. ## Type of Change - [ ] Bug fix (non-breaking change that fixes an issue) - [ ] New feature (non-breaking change that adds functionality) - [ ] Breaking change (fix or feature that would cause existing functionality to change) - [x] Documentation update - [ ] Performance improvement - [ ] Code refactoring (no functional changes) ## Changes Made - Added `docs/content/docs/ci-cd-flows.mdx` with Mermaid diagrams and decision trees for PR review, release publishing, Docker publishing, docs deploys, fork workflow approval, and manual validation. - Updated `docs/content/docs/releases.mdx` to describe the current `release-please` -> GitHub Release -> `release.yml` publishing path. - Added the CI/CD flow page and existing release page to docs navigation. - Added Mermaid to the docs code highlighter language list. - Restored missing docs helper modules and aligned Fumadocs dependencies so the docs app can install, generate sources, type-check, and build. ## Testing - [ ] Unit tests pass (`pytest`) - [ ] Linting passes (`ruff check .`) - [ ] Type checking passes (`mypy headroom`) - [ ] New tests added for new functionality - [x] Manual testing performed ### Test Output ```text $ npm ci > headroom-docs@0.0.0 postinstall > fumadocs-mdx [MDX] generated files added 365 packages, and audited 367 packages $ npm run types:check > fumadocs-mdx && next typegen && tsc --noEmit [MDX] generated files Generating route types... ✓ Types generated successfully $ npm run build > next build ✓ Compiled successfully Running TypeScript ... Generating static pages ... ✓ Generating static pages (122/122) Note: next build completed successfully and emitted two existing Recharts container-size warnings during static generation. $ git diff --check # no output $ act workflow_dispatch -W .github/workflows/docs.yml -n *DRYRUN* [Deploy Documentation/deploy] 🏁 Job succeeded ``` ## Real Behavior Proof - Environment: Windows local checkout, branch `docs-ci-flow`, Node.js v22.22.0, `act` 0.2.87. - Exact command / steps: Ran `npm ci`, `npm run types:check`, and `npm run build` from `docs/`; ran `git diff --check` and `act workflow_dispatch -W .github/workflows/docs.yml -n` from the repository root. - Observed result: Docs dependencies install, Fumadocs source generation includes `ci-cd-flows.mdx`, TypeScript passes, Next production build completes, whitespace check passes, and the docs workflow dry-run succeeds under `act`. - Not tested: Full live GitHub Pages deploy and registry/release publishing, because this PR only changes docs and docs build wiring. ## Review Readiness - [x] I have performed a self-review - [x] This PR is ready for human review ## Checklist - [x] My code follows the project's style guidelines - [x] I have performed a self-review of my code - [x] I have commented my code, particularly in hard-to-understand areas - [x] I have made corresponding changes to the documentation - [ ] My changes generate no new warnings - [ ] I have added tests that prove my fix is effective or that my feature works - [ ] New and existing unit tests pass locally with my changes - [ ] I have updated the CHANGELOG.md if applicable ## Screenshots (if applicable) N/A. This is documentation and build wiring; the diagrams are Mermaid source blocks in the docs page. ## Additional Notes - No issue is linked because this PR was not opened for a specific tracked issue. - `npm run build` still reports two pre-existing Recharts container-size warnings while completing successfully. - Python unit/lint/type checks and changelog updates are not applicable to this docs-only change.
2026-06-17 01:05:15 -05:00
"fumadocs-core": "16.10.3",
"fumadocs-mdx": "15.0.12",
2026-04-12 13:15:58 +06:00
"fumadocs-twoslash": "^3.1.3",
"fumadocs-typescript": "^4.0.3",
docs(ci): add CI/CD flow diagrams (#1062) ## Description Adds a visual CI/CD flow reference for Headroom so contributors can quickly understand the gated PR, release, Docker, docs deploy, fork approval, and manual validation paths. Also updates the release documentation to match the current release-please release flow instead of the stale push-to-main release model. ## Type of Change - [ ] Bug fix (non-breaking change that fixes an issue) - [ ] New feature (non-breaking change that adds functionality) - [ ] Breaking change (fix or feature that would cause existing functionality to change) - [x] Documentation update - [ ] Performance improvement - [ ] Code refactoring (no functional changes) ## Changes Made - Added `docs/content/docs/ci-cd-flows.mdx` with Mermaid diagrams and decision trees for PR review, release publishing, Docker publishing, docs deploys, fork workflow approval, and manual validation. - Updated `docs/content/docs/releases.mdx` to describe the current `release-please` -> GitHub Release -> `release.yml` publishing path. - Added the CI/CD flow page and existing release page to docs navigation. - Added Mermaid to the docs code highlighter language list. - Restored missing docs helper modules and aligned Fumadocs dependencies so the docs app can install, generate sources, type-check, and build. ## Testing - [ ] Unit tests pass (`pytest`) - [ ] Linting passes (`ruff check .`) - [ ] Type checking passes (`mypy headroom`) - [ ] New tests added for new functionality - [x] Manual testing performed ### Test Output ```text $ npm ci > headroom-docs@0.0.0 postinstall > fumadocs-mdx [MDX] generated files added 365 packages, and audited 367 packages $ npm run types:check > fumadocs-mdx && next typegen && tsc --noEmit [MDX] generated files Generating route types... ✓ Types generated successfully $ npm run build > next build ✓ Compiled successfully Running TypeScript ... Generating static pages ... ✓ Generating static pages (122/122) Note: next build completed successfully and emitted two existing Recharts container-size warnings during static generation. $ git diff --check # no output $ act workflow_dispatch -W .github/workflows/docs.yml -n *DRYRUN* [Deploy Documentation/deploy] 🏁 Job succeeded ``` ## Real Behavior Proof - Environment: Windows local checkout, branch `docs-ci-flow`, Node.js v22.22.0, `act` 0.2.87. - Exact command / steps: Ran `npm ci`, `npm run types:check`, and `npm run build` from `docs/`; ran `git diff --check` and `act workflow_dispatch -W .github/workflows/docs.yml -n` from the repository root. - Observed result: Docs dependencies install, Fumadocs source generation includes `ci-cd-flows.mdx`, TypeScript passes, Next production build completes, whitespace check passes, and the docs workflow dry-run succeeds under `act`. - Not tested: Full live GitHub Pages deploy and registry/release publishing, because this PR only changes docs and docs build wiring. ## Review Readiness - [x] I have performed a self-review - [x] This PR is ready for human review ## Checklist - [x] My code follows the project's style guidelines - [x] I have performed a self-review of my code - [x] I have commented my code, particularly in hard-to-understand areas - [x] I have made corresponding changes to the documentation - [ ] My changes generate no new warnings - [ ] I have added tests that prove my fix is effective or that my feature works - [ ] New and existing unit tests pass locally with my changes - [ ] I have updated the CHANGELOG.md if applicable ## Screenshots (if applicable) N/A. This is documentation and build wiring; the diagrams are Mermaid source blocks in the docs page. ## Additional Notes - No issue is linked because this PR was not opened for a specific tracked issue. - `npm run build` still reports two pre-existing Recharts container-size warnings while completing successfully. - Python unit/lint/type checks and changelog updates are not applicable to this docs-only change.
2026-06-17 01:05:15 -05:00
"fumadocs-ui": "16.10.3",
2026-04-12 13:15:58 +06:00
"headroom-ai": "file:../sdk/typescript",
"lucide-react": "^1.7.0",
"next": "16.2.6",
2026-04-12 13:15:58 +06:00
"react": "^19.2.4",
"react-dom": "^19.2.4",
"recharts": "^3.8.1",
"tailwind-merge": "^3.5.0"
},
"devDependencies": {
"@ai-sdk/openai": "^3.0.51",
fix(deps): remediate dependency CVEs and publish SBOM (#1509) ## Description Supply-chain hardening: takes the **shipped** dependency surface from **26 known CVEs to 0**. `pip install headroom-ai[all]` now resolves with no known vulnerabilities (verified with Anchore syft + grype). Also publishes a checked-in SBOM package (`sbom/`) so any user — especially pilots running their own security review — can verify what's inside and that we track it. This addresses the Dependabot alerts on `main` (9 high / 4 moderate / 7 low at time of writing). Closes # ## Type of Change - [x] Bug fix (non-breaking change that fixes an issue) - [ ] New feature (non-breaking change that adds functionality) - [ ] Breaking change (fix or feature that would cause existing functionality to change) - [x] Documentation update - [ ] Performance improvement - [ ] Code refactoring (no functional changes) ## Changes Made **Rust** - `pyo3` 0.24 → 0.29 (GHSA-36hh-v3qg-5jq4 High, GHSA-chgr-c6px-7xpp Med). Migrated `Python::allow_threads` → `Python::detach` (10 sites) and added `from_py_object` to the `Clone`-deriving `#[pyclass]` types (both required by the 0.25+ API). - `pyo3-log` 0.12 → 0.13; `lru` 0.12 → 0.18 (GHSA-rhfx-m35p-ff5j). **Python** - `torch` → 2.12.1, `mem0ai` → 2.x. - Floor-pinned transitive CVE deps via `[tool.uv] constraint-dependencies`: `pygments>=2.20.0`, `pydantic-settings>=2.14.2`, `gitpython>=3.1.50`, `langsmith>=0.9.0`. - **Removed `benchmark` from the `[all]` aggregate** so the default install is CVE-free. `lm-eval` is invoked as an external subprocess (`python -m lm_eval`) and never imported, so it is not a true runtime dep — it remains available via the opt-in `[benchmark]` extra. See [Accepted Risks](#additional-notes). **npm (build/test tooling — never shipped in the wheel/container/published SDK)** - `esbuild` override `>=0.28.1` in `sdk/typescript` + `plugins/openclaw` (GHSA-g7r4-m6w7-qqqr). - `docs/`: `@anthropic-ai/sdk` → `^0.106.0` (GHSA-p7fg-763f-g4gf), `postcss` override to force Next.js's bundled copy ≥8.5.10 (GHSA-qx2v-qp2m-jg93); regenerated a stale `bun.lock` that carried a **Critical** vitest/vite. **CI** - Pinned `pypa/gh-action-pypi-publish` `@release/v1` → `@v1.13.0` (GHSA-vxmw-7h4f-hqxh) in `release.yml` + `publish.yml`. **SBOM** - New `sbom/` directory: CycloneDX 1.7 + SPDX 2.3 SBOMs, grype scan evidence, 330-package license inventory, and a regeneration guide. ## Testing - [ ] Unit tests pass (`pytest`) — N/A, no Python source changed (deps/config only) - [x] Linting passes — `cargo fmt --check` + `cargo clippy` clean on the changed crate; 0 `.py` files changed so `ruff`/`mypy` scope is unaffected - [x] Type checking passes — `cargo check --workspace` (0 errors) - [ ] New tests added — N/A (dependency bumps; covered by existing suites) - [x] Manual testing performed — see Real Behavior Proof ### Test Output ```text # headroom-ai[all] product surface — the number that matters $ grype sbom:sbom/headroom-sbom-all-extra.cdx.json No vulnerabilities found # full repo scan (universal lock incl. opt-in [benchmark] + dev) $ grype sbom:sbom/headroom-sbom.cdx.json NAME INSTALLED TYPE VULNERABILITY SEVERITY sqlitedict 2.1.0 python GHSA-g4r7-86gm-pgqc High # [benchmark]-only, unpatchable, accepted nltk 3.9.4 python GHSA-p4gq-832x-fm9v High # [benchmark]-only, unpatchable, accepted # pyo3 0.29 migration — extension builds + imports + runs $ cargo check --workspace Finished `dev` profile [unoptimized + debuginfo] target(s) $ maturin develop && python -c "from headroom._core import DiffCompressor, SmartCrusher; ..." extension OK — detach + from_py_object paths exercised # lru 0.18 — eviction path $ cargo test -p headroom-proxy --lib drift 14 passed, 213 filtered out # per-ecosystem npm audits $ (cd sdk/typescript && npm audit) -> found 0 vulnerabilities $ (cd plugins/openclaw && npm audit) -> found 0 vulnerabilities $ (cd docs && npm audit && bun audit) -> found 0 vulnerabilities / No vulnerabilities found ``` ## Real Behavior Proof - Environment: macOS (darwin 25.4.0, arm64), Python 3.12 `.venv`, Rust 1.95 toolchain, syft 1.46.0, grype 0.115.0, bun 1.3.14, maturin 1.13.3. - Exact command / steps: (1) `uv export --extra all --no-dev --no-emit-project | syft → grype` for the product surface; (2) `cargo check --workspace` + `maturin develop` + extension import/compress smoke test; (3) `cargo test -p headroom-proxy --lib drift`; (4) `cargo fmt --check` + `cargo clippy -p headroom-py`; (5) `npm audit` in sdk/openclaw/docs + `bun audit` in docs. - Observed result: `headroom-ai[all]` resolution scans clean — "No vulnerabilities found" (179 pkgs); full/prod SBOM shows only the 2 documented accepted CVEs; pyo3 0.29 extension imports and runs (detach + from_py_object paths exercised); drift tests 14/14 pass; cargo fmt + clippy clean; all npm/bun audits report 0. - Not tested: full `pytest` suite (no Python source changed); release-profile wheel build (used dev-profile `maturin develop` for the import proof — the extension is semantically identical). ## Review Readiness - [x] I have performed a self-review - [x] This PR is ready for human review ## Checklist - [x] My code follows the project's style guidelines - [x] I have performed a self-review of my code - [x] I have commented my code, particularly in hard-to-understand areas - [x] I have made corresponding changes to the documentation (`sbom/README.md`) - [x] My changes generate no new warnings - [ ] I have added tests that prove my fix is effective — N/A (dependency bumps; existing suites + scans cover it) - [x] New and existing unit tests pass locally with my changes - [ ] I have updated the CHANGELOG.md — N/A (Release Please auto-generates from the conventional commit) ## Additional Notes **Accepted risks (the 2 residual CVEs).** Both originate solely from the EleutherAI `lm-evaluation-harness` under the **opt-in `[benchmark]` extra**, which Headroom invokes as a subprocess (never imports): - `sqlitedict` CVE-2024-35515 (High) — pickle deserialization; package abandoned (last release 2021), **no upstream fix exists**. - `nltk` CVE-2026-54293 (High) — path traversal in `nltk.data.load()`; affects ≤3.9.4 (current latest), **no patched release**. Neither is in `[all]`, the published wheel, or the container. They are documented in `sbom/README.md` and will be picked up automatically once upstream ships fixes. **Release/CHANGELOG:** N/A items above are because this is a dependency/security PR with no Python source changes; CHANGELOG is Release-Please-managed via the conventional commit message.
2026-06-27 15:28:12 -07:00
"@anthropic-ai/sdk": "^0.106.0",
2026-04-12 13:15:58 +06:00
"@tailwindcss/postcss": "^4.2.2",
"@types/mdx": "^2.0.13",
"@types/node": "^25.5.0",
"@types/react": "^19.2.14",
"@types/react-dom": "^19.2.3",
"ai": "^6.0.149",
"openai": "^6.33.0",
ci: bump the npm_and_yarn group across 3 directories with 3 updates (#1056) [//]: # (dependabot-start) ⚠️ **Dependabot is rebasing this PR** ⚠️ Rebasing might not happen immediately, so don't worry if this takes some time. Note: if you make any changes to this PR yourself, they will take precedence over the rebase. --- [//]: # (dependabot-end) Bumps the npm_and_yarn group with 1 update in the /docs directory: [js-yaml](https://github.com/nodeca/js-yaml). Bumps the npm_and_yarn group with 1 update in the /plugins/openclaw directory: [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite). Bumps the npm_and_yarn group with 2 updates in the /sdk/typescript directory: [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) and [form-data](https://github.com/form-data/form-data). Updates `js-yaml` from 4.1.1 to 4.2.0 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md">js-yaml's changelog</a>.</em></p> <blockquote> <h2>[4.2.0] - 2026-06-01</h2> <h3>Added</h3> <ul> <li>Added <code>docs/safety.md</code> with notes about processing untrusted YAML.</li> <li>Added <code>maxDepth</code> (100) loader option. Not a problem, but gives a better exception instead of RangeError on stack overflow.</li> <li>Added <code>maxMergeSeqLength</code> (20) loader option. Not a problem after <code>merge</code> fix, but an additional restriction for safety.</li> <li>Added sourcemaps to <code>dist/</code> builds.</li> </ul> <h3>Changed</h3> <ul> <li>Stop resolving numbers with underscores as numeric scalars, <a href="https://redirect.github.com/nodeca/js-yaml/issues/627">#627</a>.</li> <li>Switched dev toolchains to Vite / neostandard.</li> <li>Updated demo.</li> <li>Reorganized tests.</li> <li><code>dist/</code> files are no longer kept in the repository.</li> </ul> <h3>Fixed</h3> <ul> <li>Fix parsing of properties on the first implicit block mapping key, <a href="https://redirect.github.com/nodeca/js-yaml/issues/62">#62</a>.</li> <li>Fix trailing whitespace handling when folding flow scalar lines, <a href="https://redirect.github.com/nodeca/js-yaml/issues/307">#307</a>.</li> <li>Reject top-level block scalars without content indentation, <a href="https://redirect.github.com/nodeca/js-yaml/issues/280">#280</a>.</li> <li>Ensure numbers survive round-trip, <a href="https://redirect.github.com/nodeca/js-yaml/issues/737">#737</a>.</li> <li>Fix test coverage for issue <a href="https://redirect.github.com/nodeca/js-yaml/issues/221">#221</a>.</li> <li>Fix flow scalar trailing whitespace folding, <a href="https://redirect.github.com/nodeca/js-yaml/issues/307">#307</a>.</li> <li>Fix digits in YAML named tag handles.</li> </ul> <h3>Security</h3> <ul> <li>Fix potential DoS via quadratic complexity in merge - deduplicate repeated elements (makes sense for malformed files &gt; 10K).</li> </ul> <h2>[3.14.2] - 2025-11-15</h2> <h3>Security</h3> <ul> <li>Backported v4.1.1 fix to v3</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/nodeca/js-yaml/commits">compare view</a></li> </ul> </details> <br /> Updates `vite` from 8.0.10 to 8.0.16 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/vitejs/vite/releases">vite's releases</a>.</em></p> <blockquote> <h2>v8.0.16</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.0.16/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.0.15</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.0.15/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.0.14</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.0.14/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.0.13</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.0.13/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.0.12</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.0.12/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.0.11</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.0.11/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md">vite's changelog</a>.</em></p> <blockquote> <h2><!-- raw HTML omitted --><a href="https://github.com/vitejs/vite/compare/v8.0.15...v8.0.16">8.0.16</a> (2026-06-01)<!-- raw HTML omitted --></h2> <h3>Bug Fixes</h3> <ul> <li><strong>deps:</strong> reject UNC paths for launch-editor-middleware (<a href="https://redirect.github.com/vitejs/vite/issues/22571">#22571</a>) (<a href="https://github.com/vitejs/vite/commit/50b951225bbf6151eb84a3ad5a454908ab4a76c9">50b9512</a>)</li> <li>reject windows alternate paths (<a href="https://redirect.github.com/vitejs/vite/issues/22572">#22572</a>) (<a href="https://github.com/vitejs/vite/commit/dc245c71e5007ea4d891a025e2d69ac96c736546">dc245c7</a>)</li> </ul> <h2><!-- raw HTML omitted --><a href="https://github.com/vitejs/vite/compare/v8.0.14...v8.0.15">8.0.15</a> (2026-06-01)<!-- raw HTML omitted --></h2> <h3>Features</h3> <ul> <li>send 408 on request timeout (<a href="https://redirect.github.com/vitejs/vite/issues/22476">#22476</a>) (<a href="https://github.com/vitejs/vite/commit/c85c9eeb9aaf41f477b48b057146887bd5620797">c85c9ee</a>)</li> <li>update rolldown to 1.0.3 (<a href="https://redirect.github.com/vitejs/vite/issues/22538">#22538</a>) (<a href="https://github.com/vitejs/vite/commit/646dbedd2870f8ec48df0321177d8aa64bbd1575">646dbed</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li>capitalize error messages and remove spurious space in parse error (<a href="https://redirect.github.com/vitejs/vite/issues/22488">#22488</a>) (<a href="https://github.com/vitejs/vite/commit/85a0eff1c82bbb7c99a0fe8e63704316578a40d3">85a0eff</a>)</li> <li><strong>deps:</strong> update all non-major dependencies (<a href="https://redirect.github.com/vitejs/vite/issues/22511">#22511</a>) (<a href="https://github.com/vitejs/vite/commit/2686d7d0b722402204d3bcc687a87adea1bcf9fa">2686d7d</a>)</li> <li><strong>dev:</strong> fix html-proxy cache key mismatch for /@fs/ HTML paths (<a href="https://redirect.github.com/vitejs/vite/issues/21762">#21762</a>) (<a href="https://github.com/vitejs/vite/commit/47c4213f134f562c41ed7c031e4788510cf7e31e">47c4213</a>)</li> <li><strong>glob:</strong> error on relative glob in virtual module when no files match (<a href="https://redirect.github.com/vitejs/vite/issues/22497">#22497</a>) (<a href="https://github.com/vitejs/vite/commit/5c8e98f8b584ac5d42f0f9b8580c49792213b13c">5c8e98f</a>)</li> <li><strong>optimizer:</strong> close the rolldown bundle when write() rejects (<a href="https://redirect.github.com/vitejs/vite/issues/22528">#22528</a>) (<a href="https://github.com/vitejs/vite/commit/e3cfb9deecff563550fa1b8abd27656b8b292815">e3cfb9d</a>)</li> <li><strong>resolve:</strong> provide onWarn for viteResolvePlugin in JS plugin containers (<a href="https://redirect.github.com/vitejs/vite/issues/22509">#22509</a>) (<a href="https://github.com/vitejs/vite/commit/40985f1c09b7696e594e6c5695fbc315d2da2c83">40985f1</a>)</li> </ul> <h3>Miscellaneous Chores</h3> <ul> <li><strong>deps:</strong> update rolldown-related dependencies (<a href="https://redirect.github.com/vitejs/vite/issues/22566">#22566</a>) (<a href="https://github.com/vitejs/vite/commit/3052a67d9350f4c5076ab1c222c4a21a589cbcdd">3052a67</a>)</li> </ul> <h3>Code Refactoring</h3> <ul> <li>correct logic in <code>collectAllModules</code> function (<a href="https://redirect.github.com/vitejs/vite/issues/22562">#22562</a>) (<a href="https://github.com/vitejs/vite/commit/6978a9ceb942c4f5e211d52b8a1e569f8a65c80c">6978a9c</a>)</li> </ul> <h2><!-- raw HTML omitted --><a href="https://github.com/vitejs/vite/compare/v8.0.13...v8.0.14">8.0.14</a> (2026-05-21)<!-- raw HTML omitted --></h2> <h3>Features</h3> <ul> <li>update rolldown to 1.0.2 (<a href="https://redirect.github.com/vitejs/vite/issues/22484">#22484</a>) (<a href="https://github.com/vitejs/vite/commit/96efc88570b6a6ddf1a910f106920cbac07b3cf0">96efc88</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li><strong>deps:</strong> update all non-major dependencies (<a href="https://redirect.github.com/vitejs/vite/issues/22471">#22471</a>) (<a href="https://github.com/vitejs/vite/commit/98b81632139d51820f82036e58d6fbbf122b77b3">98b8163</a>)</li> <li><strong>dev:</strong> handle errors when sending messages to vite server (<a href="https://redirect.github.com/vitejs/vite/issues/22450">#22450</a>) (<a href="https://github.com/vitejs/vite/commit/e8e9a34dcf2540139de558a10187630884d10217">e8e9a34</a>)</li> <li><strong>html:</strong> handle trailing slash paths in transformIndexHtml (<a href="https://redirect.github.com/vitejs/vite/issues/22480">#22480</a>) (<a href="https://github.com/vitejs/vite/commit/5d94d1bffdb2a15de9341194d89baec86ce1f693">5d94d1b</a>)</li> <li><strong>optimizer:</strong> pass oxc jsx options to transformSync in dependency scan (<a href="https://redirect.github.com/vitejs/vite/issues/22342">#22342</a>) (<a href="https://github.com/vitejs/vite/commit/b3132dacea9c6e0cf526cd9f0f09d850f577c262">b3132da</a>)</li> </ul> <h3>Miscellaneous Chores</h3> <ul> <li><strong>deps:</strong> update rolldown-related dependencies (<a href="https://redirect.github.com/vitejs/vite/issues/22470">#22470</a>) (<a href="https://github.com/vitejs/vite/commit/7cb728eb629cc677661f1bc52a044ffc0b87fc7f">7cb728e</a>)</li> <li>remove irrelevant commits from changelog (<a href="https://github.com/vitejs/vite/commit/2c69495f250edf01132d4a20128de19dbe836086">2c69495</a>)</li> </ul> <h3>Code Refactoring</h3> <ul> <li><strong>glob:</strong> do not rewrite import path for absolute base (<a href="https://redirect.github.com/vitejs/vite/issues/22310">#22310</a>) (<a href="https://github.com/vitejs/vite/commit/0ae2844ab6d6d1ccf78a2975b8132769fc35b302">0ae2844</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/vitejs/vite/commit/f94df87ff03b40b65e29bacdc04cc18c7bccaa4a"><code>f94df87</code></a> release: v8.0.16</li> <li><a href="https://github.com/vitejs/vite/commit/dc245c71e5007ea4d891a025e2d69ac96c736546"><code>dc245c7</code></a> fix: reject windows alternate paths (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22572">#22572</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/50b951225bbf6151eb84a3ad5a454908ab4a76c9"><code>50b9512</code></a> fix(deps): reject UNC paths for launch-editor-middleware (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22571">#22571</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/8d1b0195fd186d0b3297d7cd17acff6c96797420"><code>8d1b019</code></a> release: v8.0.15</li> <li><a href="https://github.com/vitejs/vite/commit/2686d7d0b722402204d3bcc687a87adea1bcf9fa"><code>2686d7d</code></a> fix(deps): update all non-major dependencies (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22511">#22511</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/3052a67d9350f4c5076ab1c222c4a21a589cbcdd"><code>3052a67</code></a> chore(deps): update rolldown-related dependencies (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22566">#22566</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/e3cfb9deecff563550fa1b8abd27656b8b292815"><code>e3cfb9d</code></a> fix(optimizer): close the rolldown bundle when write() rejects (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22528">#22528</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/6978a9ceb942c4f5e211d52b8a1e569f8a65c80c"><code>6978a9c</code></a> refactor: correct logic in <code>collectAllModules</code> function (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22562">#22562</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/646dbedd2870f8ec48df0321177d8aa64bbd1575"><code>646dbed</code></a> feat: update rolldown to 1.0.3 (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22538">#22538</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/85a0eff1c82bbb7c99a0fe8e63704316578a40d3"><code>85a0eff</code></a> fix: capitalize error messages and remove spurious space in parse error (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22488">#22488</a>)</li> <li>Additional commits viewable in <a href="https://github.com/vitejs/vite/commits/v8.0.16/packages/vite">compare view</a></li> </ul> </details> <br /> Updates `vite` from 8.0.10 to 8.0.16 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/vitejs/vite/releases">vite's releases</a>.</em></p> <blockquote> <h2>v8.0.16</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.0.16/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.0.15</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.0.15/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.0.14</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.0.14/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.0.13</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.0.13/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.0.12</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.0.12/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.0.11</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.0.11/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md">vite's changelog</a>.</em></p> <blockquote> <h2><!-- raw HTML omitted --><a href="https://github.com/vitejs/vite/compare/v8.0.15...v8.0.16">8.0.16</a> (2026-06-01)<!-- raw HTML omitted --></h2> <h3>Bug Fixes</h3> <ul> <li><strong>deps:</strong> reject UNC paths for launch-editor-middleware (<a href="https://redirect.github.com/vitejs/vite/issues/22571">#22571</a>) (<a href="https://github.com/vitejs/vite/commit/50b951225bbf6151eb84a3ad5a454908ab4a76c9">50b9512</a>)</li> <li>reject windows alternate paths (<a href="https://redirect.github.com/vitejs/vite/issues/22572">#22572</a>) (<a href="https://github.com/vitejs/vite/commit/dc245c71e5007ea4d891a025e2d69ac96c736546">dc245c7</a>)</li> </ul> <h2><!-- raw HTML omitted --><a href="https://github.com/vitejs/vite/compare/v8.0.14...v8.0.15">8.0.15</a> (2026-06-01)<!-- raw HTML omitted --></h2> <h3>Features</h3> <ul> <li>send 408 on request timeout (<a href="https://redirect.github.com/vitejs/vite/issues/22476">#22476</a>) (<a href="https://github.com/vitejs/vite/commit/c85c9eeb9aaf41f477b48b057146887bd5620797">c85c9ee</a>)</li> <li>update rolldown to 1.0.3 (<a href="https://redirect.github.com/vitejs/vite/issues/22538">#22538</a>) (<a href="https://github.com/vitejs/vite/commit/646dbedd2870f8ec48df0321177d8aa64bbd1575">646dbed</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li>capitalize error messages and remove spurious space in parse error (<a href="https://redirect.github.com/vitejs/vite/issues/22488">#22488</a>) (<a href="https://github.com/vitejs/vite/commit/85a0eff1c82bbb7c99a0fe8e63704316578a40d3">85a0eff</a>)</li> <li><strong>deps:</strong> update all non-major dependencies (<a href="https://redirect.github.com/vitejs/vite/issues/22511">#22511</a>) (<a href="https://github.com/vitejs/vite/commit/2686d7d0b722402204d3bcc687a87adea1bcf9fa">2686d7d</a>)</li> <li><strong>dev:</strong> fix html-proxy cache key mismatch for /@fs/ HTML paths (<a href="https://redirect.github.com/vitejs/vite/issues/21762">#21762</a>) (<a href="https://github.com/vitejs/vite/commit/47c4213f134f562c41ed7c031e4788510cf7e31e">47c4213</a>)</li> <li><strong>glob:</strong> error on relative glob in virtual module when no files match (<a href="https://redirect.github.com/vitejs/vite/issues/22497">#22497</a>) (<a href="https://github.com/vitejs/vite/commit/5c8e98f8b584ac5d42f0f9b8580c49792213b13c">5c8e98f</a>)</li> <li><strong>optimizer:</strong> close the rolldown bundle when write() rejects (<a href="https://redirect.github.com/vitejs/vite/issues/22528">#22528</a>) (<a href="https://github.com/vitejs/vite/commit/e3cfb9deecff563550fa1b8abd27656b8b292815">e3cfb9d</a>)</li> <li><strong>resolve:</strong> provide onWarn for viteResolvePlugin in JS plugin containers (<a href="https://redirect.github.com/vitejs/vite/issues/22509">#22509</a>) (<a href="https://github.com/vitejs/vite/commit/40985f1c09b7696e594e6c5695fbc315d2da2c83">40985f1</a>)</li> </ul> <h3>Miscellaneous Chores</h3> <ul> <li><strong>deps:</strong> update rolldown-related dependencies (<a href="https://redirect.github.com/vitejs/vite/issues/22566">#22566</a>) (<a href="https://github.com/vitejs/vite/commit/3052a67d9350f4c5076ab1c222c4a21a589cbcdd">3052a67</a>)</li> </ul> <h3>Code Refactoring</h3> <ul> <li>correct logic in <code>collectAllModules</code> function (<a href="https://redirect.github.com/vitejs/vite/issues/22562">#22562</a>) (<a href="https://github.com/vitejs/vite/commit/6978a9ceb942c4f5e211d52b8a1e569f8a65c80c">6978a9c</a>)</li> </ul> <h2><!-- raw HTML omitted --><a href="https://github.com/vitejs/vite/compare/v8.0.13...v8.0.14">8.0.14</a> (2026-05-21)<!-- raw HTML omitted --></h2> <h3>Features</h3> <ul> <li>update rolldown to 1.0.2 (<a href="https://redirect.github.com/vitejs/vite/issues/22484">#22484</a>) (<a href="https://github.com/vitejs/vite/commit/96efc88570b6a6ddf1a910f106920cbac07b3cf0">96efc88</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li><strong>deps:</strong> update all non-major dependencies (<a href="https://redirect.github.com/vitejs/vite/issues/22471">#22471</a>) (<a href="https://github.com/vitejs/vite/commit/98b81632139d51820f82036e58d6fbbf122b77b3">98b8163</a>)</li> <li><strong>dev:</strong> handle errors when sending messages to vite server (<a href="https://redirect.github.com/vitejs/vite/issues/22450">#22450</a>) (<a href="https://github.com/vitejs/vite/commit/e8e9a34dcf2540139de558a10187630884d10217">e8e9a34</a>)</li> <li><strong>html:</strong> handle trailing slash paths in transformIndexHtml (<a href="https://redirect.github.com/vitejs/vite/issues/22480">#22480</a>) (<a href="https://github.com/vitejs/vite/commit/5d94d1bffdb2a15de9341194d89baec86ce1f693">5d94d1b</a>)</li> <li><strong>optimizer:</strong> pass oxc jsx options to transformSync in dependency scan (<a href="https://redirect.github.com/vitejs/vite/issues/22342">#22342</a>) (<a href="https://github.com/vitejs/vite/commit/b3132dacea9c6e0cf526cd9f0f09d850f577c262">b3132da</a>)</li> </ul> <h3>Miscellaneous Chores</h3> <ul> <li><strong>deps:</strong> update rolldown-related dependencies (<a href="https://redirect.github.com/vitejs/vite/issues/22470">#22470</a>) (<a href="https://github.com/vitejs/vite/commit/7cb728eb629cc677661f1bc52a044ffc0b87fc7f">7cb728e</a>)</li> <li>remove irrelevant commits from changelog (<a href="https://github.com/vitejs/vite/commit/2c69495f250edf01132d4a20128de19dbe836086">2c69495</a>)</li> </ul> <h3>Code Refactoring</h3> <ul> <li><strong>glob:</strong> do not rewrite import path for absolute base (<a href="https://redirect.github.com/vitejs/vite/issues/22310">#22310</a>) (<a href="https://github.com/vitejs/vite/commit/0ae2844ab6d6d1ccf78a2975b8132769fc35b302">0ae2844</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/vitejs/vite/commit/f94df87ff03b40b65e29bacdc04cc18c7bccaa4a"><code>f94df87</code></a> release: v8.0.16</li> <li><a href="https://github.com/vitejs/vite/commit/dc245c71e5007ea4d891a025e2d69ac96c736546"><code>dc245c7</code></a> fix: reject windows alternate paths (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22572">#22572</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/50b951225bbf6151eb84a3ad5a454908ab4a76c9"><code>50b9512</code></a> fix(deps): reject UNC paths for launch-editor-middleware (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22571">#22571</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/8d1b0195fd186d0b3297d7cd17acff6c96797420"><code>8d1b019</code></a> release: v8.0.15</li> <li><a href="https://github.com/vitejs/vite/commit/2686d7d0b722402204d3bcc687a87adea1bcf9fa"><code>2686d7d</code></a> fix(deps): update all non-major dependencies (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22511">#22511</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/3052a67d9350f4c5076ab1c222c4a21a589cbcdd"><code>3052a67</code></a> chore(deps): update rolldown-related dependencies (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22566">#22566</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/e3cfb9deecff563550fa1b8abd27656b8b292815"><code>e3cfb9d</code></a> fix(optimizer): close the rolldown bundle when write() rejects (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22528">#22528</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/6978a9ceb942c4f5e211d52b8a1e569f8a65c80c"><code>6978a9c</code></a> refactor: correct logic in <code>collectAllModules</code> function (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22562">#22562</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/646dbedd2870f8ec48df0321177d8aa64bbd1575"><code>646dbed</code></a> feat: update rolldown to 1.0.3 (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22538">#22538</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/85a0eff1c82bbb7c99a0fe8e63704316578a40d3"><code>85a0eff</code></a> fix: capitalize error messages and remove spurious space in parse error (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22488">#22488</a>)</li> <li>Additional commits viewable in <a href="https://github.com/vitejs/vite/commits/v8.0.16/packages/vite">compare view</a></li> </ul> </details> <br /> Updates `form-data` from 4.0.5 to 4.0.6 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/form-data/form-data/blob/master/CHANGELOG.md">form-data's changelog</a>.</em></p> <blockquote> <h2><a href="https://github.com/form-data/form-data/compare/v4.0.5...v4.0.6">v4.0.6</a> - 2026-06-12</h2> <h3>Commits</h3> <ul> <li>[Fix] escape CR, LF, and <code>&quot;</code> in field names and filenames <a href="https://github.com/form-data/form-data/commit/8dff42c6da654ed4e7ad4acb7f8ccd3831217c99"><code>8dff42c</code></a></li> <li>[Dev Deps] update <code>@ljharb/eslint-config</code>, <code>auto-changelog</code>, <code>tape</code> <a href="https://github.com/form-data/form-data/commit/f31d21ef10bf46e46344c3ee4f99acbef6be43e1"><code>f31d21e</code></a></li> <li>[Deps] update <code>hasown</code>, <code>mime-types</code> <a href="https://github.com/form-data/form-data/commit/92ae0eb5da94d6f01925d5f4fcffb2a1e50ed7cd"><code>92ae0eb</code></a></li> <li>[Dev Deps] update <code>js-randomness-predictor</code> <a href="https://github.com/form-data/form-data/commit/67b0f65c2e0b065a511d42227d35e4d367644e97"><code>67b0f65</code></a></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/form-data/form-data/commit/64190db548c0179e37206858e39f27cf513e9435"><code>64190db</code></a> v4.0.6</li> <li><a href="https://github.com/form-data/form-data/commit/92ae0eb5da94d6f01925d5f4fcffb2a1e50ed7cd"><code>92ae0eb</code></a> [Deps] update <code>hasown</code>, <code>mime-types</code></li> <li><a href="https://github.com/form-data/form-data/commit/f31d21ef10bf46e46344c3ee4f99acbef6be43e1"><code>f31d21e</code></a> [Dev Deps] update <code>@ljharb/eslint-config</code>, <code>auto-changelog</code>, <code>tape</code></li> <li><a href="https://github.com/form-data/form-data/commit/8dff42c6da654ed4e7ad4acb7f8ccd3831217c99"><code>8dff42c</code></a> [Fix] escape CR, LF, and <code>&quot;</code> in field names and filenames</li> <li><a href="https://github.com/form-data/form-data/commit/67b0f65c2e0b065a511d42227d35e4d367644e97"><code>67b0f65</code></a> [Dev Deps] update <code>js-randomness-predictor</code></li> <li>See full diff in <a href="https://github.com/form-data/form-data/compare/v4.0.5...v4.0.6">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/chopratejas/headroom/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-16 23:07:34 -07:00
"postcss": "^8.5.13",
2026-04-12 13:15:58 +06:00
"tailwindcss": "^4.2.2",
"typescript": "^5.9.3"
fix(deps): remediate dependency CVEs and publish SBOM (#1509) ## Description Supply-chain hardening: takes the **shipped** dependency surface from **26 known CVEs to 0**. `pip install headroom-ai[all]` now resolves with no known vulnerabilities (verified with Anchore syft + grype). Also publishes a checked-in SBOM package (`sbom/`) so any user — especially pilots running their own security review — can verify what's inside and that we track it. This addresses the Dependabot alerts on `main` (9 high / 4 moderate / 7 low at time of writing). Closes # ## Type of Change - [x] Bug fix (non-breaking change that fixes an issue) - [ ] New feature (non-breaking change that adds functionality) - [ ] Breaking change (fix or feature that would cause existing functionality to change) - [x] Documentation update - [ ] Performance improvement - [ ] Code refactoring (no functional changes) ## Changes Made **Rust** - `pyo3` 0.24 → 0.29 (GHSA-36hh-v3qg-5jq4 High, GHSA-chgr-c6px-7xpp Med). Migrated `Python::allow_threads` → `Python::detach` (10 sites) and added `from_py_object` to the `Clone`-deriving `#[pyclass]` types (both required by the 0.25+ API). - `pyo3-log` 0.12 → 0.13; `lru` 0.12 → 0.18 (GHSA-rhfx-m35p-ff5j). **Python** - `torch` → 2.12.1, `mem0ai` → 2.x. - Floor-pinned transitive CVE deps via `[tool.uv] constraint-dependencies`: `pygments>=2.20.0`, `pydantic-settings>=2.14.2`, `gitpython>=3.1.50`, `langsmith>=0.9.0`. - **Removed `benchmark` from the `[all]` aggregate** so the default install is CVE-free. `lm-eval` is invoked as an external subprocess (`python -m lm_eval`) and never imported, so it is not a true runtime dep — it remains available via the opt-in `[benchmark]` extra. See [Accepted Risks](#additional-notes). **npm (build/test tooling — never shipped in the wheel/container/published SDK)** - `esbuild` override `>=0.28.1` in `sdk/typescript` + `plugins/openclaw` (GHSA-g7r4-m6w7-qqqr). - `docs/`: `@anthropic-ai/sdk` → `^0.106.0` (GHSA-p7fg-763f-g4gf), `postcss` override to force Next.js's bundled copy ≥8.5.10 (GHSA-qx2v-qp2m-jg93); regenerated a stale `bun.lock` that carried a **Critical** vitest/vite. **CI** - Pinned `pypa/gh-action-pypi-publish` `@release/v1` → `@v1.13.0` (GHSA-vxmw-7h4f-hqxh) in `release.yml` + `publish.yml`. **SBOM** - New `sbom/` directory: CycloneDX 1.7 + SPDX 2.3 SBOMs, grype scan evidence, 330-package license inventory, and a regeneration guide. ## Testing - [ ] Unit tests pass (`pytest`) — N/A, no Python source changed (deps/config only) - [x] Linting passes — `cargo fmt --check` + `cargo clippy` clean on the changed crate; 0 `.py` files changed so `ruff`/`mypy` scope is unaffected - [x] Type checking passes — `cargo check --workspace` (0 errors) - [ ] New tests added — N/A (dependency bumps; covered by existing suites) - [x] Manual testing performed — see Real Behavior Proof ### Test Output ```text # headroom-ai[all] product surface — the number that matters $ grype sbom:sbom/headroom-sbom-all-extra.cdx.json No vulnerabilities found # full repo scan (universal lock incl. opt-in [benchmark] + dev) $ grype sbom:sbom/headroom-sbom.cdx.json NAME INSTALLED TYPE VULNERABILITY SEVERITY sqlitedict 2.1.0 python GHSA-g4r7-86gm-pgqc High # [benchmark]-only, unpatchable, accepted nltk 3.9.4 python GHSA-p4gq-832x-fm9v High # [benchmark]-only, unpatchable, accepted # pyo3 0.29 migration — extension builds + imports + runs $ cargo check --workspace Finished `dev` profile [unoptimized + debuginfo] target(s) $ maturin develop && python -c "from headroom._core import DiffCompressor, SmartCrusher; ..." extension OK — detach + from_py_object paths exercised # lru 0.18 — eviction path $ cargo test -p headroom-proxy --lib drift 14 passed, 213 filtered out # per-ecosystem npm audits $ (cd sdk/typescript && npm audit) -> found 0 vulnerabilities $ (cd plugins/openclaw && npm audit) -> found 0 vulnerabilities $ (cd docs && npm audit && bun audit) -> found 0 vulnerabilities / No vulnerabilities found ``` ## Real Behavior Proof - Environment: macOS (darwin 25.4.0, arm64), Python 3.12 `.venv`, Rust 1.95 toolchain, syft 1.46.0, grype 0.115.0, bun 1.3.14, maturin 1.13.3. - Exact command / steps: (1) `uv export --extra all --no-dev --no-emit-project | syft → grype` for the product surface; (2) `cargo check --workspace` + `maturin develop` + extension import/compress smoke test; (3) `cargo test -p headroom-proxy --lib drift`; (4) `cargo fmt --check` + `cargo clippy -p headroom-py`; (5) `npm audit` in sdk/openclaw/docs + `bun audit` in docs. - Observed result: `headroom-ai[all]` resolution scans clean — "No vulnerabilities found" (179 pkgs); full/prod SBOM shows only the 2 documented accepted CVEs; pyo3 0.29 extension imports and runs (detach + from_py_object paths exercised); drift tests 14/14 pass; cargo fmt + clippy clean; all npm/bun audits report 0. - Not tested: full `pytest` suite (no Python source changed); release-profile wheel build (used dev-profile `maturin develop` for the import proof — the extension is semantically identical). ## Review Readiness - [x] I have performed a self-review - [x] This PR is ready for human review ## Checklist - [x] My code follows the project's style guidelines - [x] I have performed a self-review of my code - [x] I have commented my code, particularly in hard-to-understand areas - [x] I have made corresponding changes to the documentation (`sbom/README.md`) - [x] My changes generate no new warnings - [ ] I have added tests that prove my fix is effective — N/A (dependency bumps; existing suites + scans cover it) - [x] New and existing unit tests pass locally with my changes - [ ] I have updated the CHANGELOG.md — N/A (Release Please auto-generates from the conventional commit) ## Additional Notes **Accepted risks (the 2 residual CVEs).** Both originate solely from the EleutherAI `lm-evaluation-harness` under the **opt-in `[benchmark]` extra**, which Headroom invokes as a subprocess (never imports): - `sqlitedict` CVE-2024-35515 (High) — pickle deserialization; package abandoned (last release 2021), **no upstream fix exists**. - `nltk` CVE-2026-54293 (High) — path traversal in `nltk.data.load()`; affects ≤3.9.4 (current latest), **no patched release**. Neither is in `[all]`, the published wheel, or the container. They are documented in `sbom/README.md` and will be picked up automatically once upstream ships fixes. **Release/CHANGELOG:** N/A items above are because this is a dependency/security PR with no Python source changes; CHANGELOG is Release-Please-managed via the conventional commit message.
2026-06-27 15:28:12 -07:00
},
"overrides": {
"postcss": "$postcss"
2026-04-12 13:15:58 +06:00
}
}