mirror of
https://github.com/vercel/workflow.git
synced 2026-09-14 19:59:43 +08:00
b92dfbb94d
Astro <6.4.6 is vulnerable to CVE-2026-54299 (GHSA-2pvr-wf23-7pc7, host header SSRF in prerendered error page fetch). The fix only exists in the 6.x line — there is no 5.x backport — so this bumps: - workbench/astro: astro ^6.4.6, @astrojs/node 10.1.4, @astrojs/vercel ^10.0.8 - packages/astro: astro devDependency 6.4.6 (typecheck only, not shipped) Removes both vulnerable astro@5.16.3 and astro@5.18.0 from the lockfile. Verified the example app builds under both the node and vercel adapters. Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
29 lines
794 B
JSON
29 lines
794 B
JSON
{
|
|
"name": "@workflow/example-astro",
|
|
"private": true,
|
|
"type": "module",
|
|
"version": "0.0.0",
|
|
"scripts": {
|
|
"generate:workflows": "node ../scripts/generate-workflows-registry.js ./src/workflows src/lib/_workflows.ts",
|
|
"predev": "pnpm generate:workflows",
|
|
"prebuild": "pnpm generate:workflows",
|
|
"dev": "astro dev",
|
|
"build": "astro build",
|
|
"preview": "astro preview",
|
|
"astro": "astro",
|
|
"start": "node scripts/start-with-pg.mjs"
|
|
},
|
|
"dependencies": {
|
|
"@astrojs/node": "10.1.4",
|
|
"@astrojs/vercel": "^10.0.8",
|
|
"ai": "catalog:",
|
|
"astro": "^6.4.6",
|
|
"lodash.chunk": "^4.2.0",
|
|
"openai": "6.9.0",
|
|
"workflow": "workspace:*",
|
|
"@workflow/ai": "workspace:*",
|
|
"@workflow/world-postgres": "workspace:*",
|
|
"zod": "catalog:"
|
|
}
|
|
}
|