Files
accounted/package.json
T
Jakob Wennberg 922cf16227 fix(deps): override postcss to 8.5.18+ to clear two HIGH CVEs (#1235)
The daily lockfile SCA scan was failing on CVE-2026-45623 and GHSA-r28c-9q8g-f849, both disclosed 2026-07-27: PostCSS auto-loads a source map from an attacker-controlled sourceMappingURL comment, giving arbitrary .map file read on any CSS the toolchain does not fully trust.

Same nested-dependency shape as the sharp fix in #1223, and worse in one respect: next pins its own postcss@8.4.31, but the top-level was vulnerable too at 8.5.16 against a fix that landed in 8.5.18. One override collapses both onto 8.5.23 and drops the nested copy.

postcss is build-critical for Tailwind 4, so this was verified past 'tests pass': the production build succeeds and emits a 166 KB compiled CSS chunk with Tailwind utility classes intact. Full unit suite 11,359 passed.
2026-07-27 14:27:18 +02:00

102 lines
3.3 KiB
JSON

{
"name": "erp-base",
"version": "0.1.0",
"private": true,
"license": "AGPL-3.0-or-later",
"scripts": {
"setup:extensions": "npx tsx scripts/generate-extension-registry.ts",
"skills:generate": "npx tsx scripts/generate-skill-bodies.ts",
"skills:check": "npx tsx scripts/generate-skill-bodies.ts --check",
"crontabs:generate": "npx tsx scripts/generate-crontabs.ts",
"taxonomy:generate": "npx tsx scripts/generate-taxonomy-registry.ts",
"taxonomy:check": "npx tsx scripts/generate-taxonomy-registry.ts --check",
"validate:ixbrl": "node scripts/validate-ixbrl.mjs",
"predev": "npm run setup:extensions && node scripts/inject-public-branding.mjs",
"dev": "next dev",
"prebuild": "npm run setup:extensions && node scripts/inject-public-branding.mjs",
"build": "next build",
"start": "next start",
"lint": "eslint",
"check:guards": "node scripts/checks/no-new-antipatterns.mjs",
"check:lint": "node scripts/checks/no-new-lint-errors.mjs",
"test": "vitest run --project unit",
"test:pg": "vitest run --project pg-real"
},
"dependencies": {
"@anthropic-ai/bedrock-sdk": "0.29.1",
"@hookform/resolvers": "^5.4.0",
"@radix-ui/react-checkbox": "^1.3.7",
"@radix-ui/react-dialog": "^1.1.19",
"@radix-ui/react-dropdown-menu": "^2.1.20",
"@radix-ui/react-label": "^2.1.11",
"@radix-ui/react-progress": "^1.1.12",
"@radix-ui/react-select": "^2.3.3",
"@radix-ui/react-slot": "^1.2.4",
"@radix-ui/react-switch": "^1.3.3",
"@radix-ui/react-tabs": "^1.1.17",
"@radix-ui/react-toast": "^1.2.19",
"@radix-ui/react-tooltip": "^1.2.12",
"@react-pdf/renderer": "^4.5.1",
"@supabase/ssr": "^0.12.1",
"@supabase/supabase-js": "^2.110.1",
"@tailwindcss/typography": "^0.5.20",
"@types/qrcode": "^1.5.6",
"@upstash/ratelimit": "^2.0.8",
"@upstash/redis": "^1.38.0",
"@use-gesture/react": "^10.3.1",
"@vercel/speed-insights": "^2.0.0",
"class-variance-authority": "^0.7.1",
"clsx": "^2.1.1",
"date-fns": "^4.4.0",
"framer-motion": "^12.42.2",
"fuse.js": "^7.4.2",
"ics": "^3.12.0",
"jszip": "^3.10.1",
"lucide-react": "^1.24.0",
"mailparser": "^3.9.14",
"next": "16.2.12",
"next-intl": "^4.13.2",
"next-themes": "^0.4.6",
"pdf-lib": "^1.17.1",
"qrcode": "^1.5.4",
"react": "19.2.7",
"react-dom": "19.2.7",
"react-hook-form": "^7.80.0",
"react-markdown": "^10.1.0",
"recharts": "^3.9.1",
"remark-gfm": "^4.0.1",
"resend": "^6.17.2",
"server-only": "^0.0.1",
"sharp": "^0.35.3",
"stripe": "^22.3.1",
"svix": "^1.85.0",
"swr": "^2.4.2",
"tailwind-merge": "^3.6.0",
"web-push": "^3.6.7",
"xlsx": "https://cdn.sheetjs.com/xlsx-0.20.3/xlsx-0.20.3.tgz",
"zod": "^4.4.3"
},
"devDependencies": {
"@tailwindcss/postcss": "^4",
"@types/mailparser": "^3.4.6",
"@types/node": "^20",
"@types/pg": "^8.20.0",
"@types/react": "^19",
"@types/react-dom": "^19",
"@types/sharp": "^0.32.0",
"@types/web-push": "^3.6.4",
"dotenv": "^17.4.2",
"eslint": "^9",
"eslint-config-next": "16.2.12",
"pg": "^8.22.0",
"tailwindcss": "^4",
"typescript": "^5",
"vitest": "^4.1.9"
},
"overrides": {
"ws": "^8.21.0",
"sharp": "^0.35.3",
"postcss": "^8.5.18"
}
}