From 14a92e5444b23354b9f9480b3397c4192ee7314a Mon Sep 17 00:00:00 2001 From: Alex Villarreal <716334+alexvy86@users.noreply.github.com> Date: Tue, 12 May 2026 17:42:20 -0500 Subject: [PATCH 1/3] Add overrides to pnpm workspace for compat installs to address CVEs --- .../compat-workspaces/full/pnpm-lock.yaml | 328 ++++++++---------- .../full/pnpm-workspace.yaml | 12 +- 2 files changed, 161 insertions(+), 179 deletions(-) diff --git a/packages/test/test-version-utils/compat-workspaces/full/pnpm-lock.yaml b/packages/test/test-version-utils/compat-workspaces/full/pnpm-lock.yaml index 84df092c7490..1037796c3d33 100644 --- a/packages/test/test-version-utils/compat-workspaces/full/pnpm-lock.yaml +++ b/packages/test/test-version-utils/compat-workspaces/full/pnpm-lock.yaml @@ -4,6 +4,13 @@ settings: autoInstallPeers: true excludeLinksFromLockfile: false +overrides: + axios@<1: ^0.31.1 + axios@>=1 <2: ^1.15.2 + jsrsasign@<12: ^11.1.1 + serialize-javascript@>=6 <7: ^7.0.5 + uuid@>=11 <12: ^11.1.1 + importers: .: {} @@ -3291,17 +3298,11 @@ packages: resolution: {integrity: sha512-wvUjBtSGN7+7SjNpq/9M2Tg350UZD3q62IFZLbRAR1bSMlCo1ZaeW+BJ+D090e4hIIZLBcTDWe4Mh4jvUDajzQ==} engines: {node: '>= 0.4'} - axios@0.21.4: - resolution: {integrity: sha512-ut5vewkiu8jjGBdqpM44XxjuCjq9LAKeHVmoVfHVzy8eHgxxq8SbAVQNovDA8mVi05kP0Ea/n/UzcSHcTJQfNg==} - - axios@0.26.1: - resolution: {integrity: sha512-fPwcX4EvnSHuInCMItEhAGnaSEXRBjtzh9fOtsE6E1G6p7vl7edEeZe11QHf18+6+9gR5PbKV/sGKNaD8YaMeA==} - - axios@0.28.1: - resolution: {integrity: sha512-iUcGA5a7p0mVb4Gm/sy+FSECNkPFT4y7wt6OM/CDpO/OnNCvSs3PoMG8ibrC9jRoGYU0gUK5pXVC4NPXq6lHRQ==} + axios@0.31.1: + resolution: {integrity: sha512-Ef8DUZSZQP6igY48mjGaoEjwhely97lserep0IFJifBH4YdKvwH5eMLniy3kig2HQoBNR8EkZpDjowxwTJcmbg==} - axios@1.15.0: - resolution: {integrity: sha512-wWyJDlAatxk30ZJer+GeCWS209sA42X+N5jU2jy6oHTp7ufw8uzUTVFBX9+wTfAlhiJXGS0Bq7X6efruWjuK9Q==} + axios@1.16.0: + resolution: {integrity: sha512-6hp5CwvTPlN2A31g5dxnwAX0orzM7pmCRDLnZSX772mv8WDqICwFjowHuPs04Mc8deIld1+ejhtaMn5vp6b+1w==} backo2@1.0.2: resolution: {integrity: sha512-zj6Z6M7Eq+PBZ7PQxl5NT665MvJdAkzp0f60nAJ+sLaSCBPMwVak5ZegFbgVCzFcCJTKFoMizvM5Ld7+JrRJHA==} @@ -3712,9 +3713,6 @@ packages: json-stringify-safe@5.0.1: resolution: {integrity: sha512-ZClg6AaYvamvYEE82d3Iyd3vSSIjQ+odgjaTzRuO3s7toCdFKczob2i0zCh7JE8kWn17yvAWhUVxvqGwUalsRA==} - jsrsasign@10.9.0: - resolution: {integrity: sha512-QWLUikj1SBJGuyGK8tjKSx3K7Y69KYJnrs/pQ1KZ6wvZIkHkWjZ1PJDpuvc1/28c1uP0KW9qn1eI1LzHQqDOwQ==} - jsrsasign@11.1.2: resolution: {integrity: sha512-GJuqiU/Grs6BaBBXMAZM9kxhsBrksZE0pF3qIfpkopMd7OMJ9zZmE/+CpV//97srfEyyyq1Ec0ELQtSlW/gPTA==} @@ -3875,9 +3873,6 @@ packages: querystringify@2.2.0: resolution: {integrity: sha512-FIqgj2EUvTa7R50u0rGsyTftzjYmv/a3hO345bZNrqabNqjtgiDMgmo4mkUjd+nzU5oF3dClKqFIPUKybUyqoQ==} - randombytes@2.1.0: - resolution: {integrity: sha512-vYl3iOX+4CKUWuxGi9Ukhie6fsqXqS9FE2Zaic4tNFD2N2QQaXOMFbuKK4QmDHC0JO6B1Zp41J0LpT0oR68amQ==} - readdirp@3.6.0: resolution: {integrity: sha512-hOS089on8RduqdbhvQ5Z37A0ESjsqz6qnRcffsMU3495FuTdqSm+7bhJ29JvIOsBDEEnan5DPu9t3To9VRlMzA==} engines: {node: '>=8.10.0'} @@ -3928,8 +3923,9 @@ packages: resolution: {integrity: sha512-3NnuWfM6vBYoy5gZFvHiYsVbafvI9vZv/+jlIigFn4oP4zjNPK3LhcY0xSCgeb1a5L8jO71Mit9LlNoi2UfDDQ==} engines: {node: '>=10'} - serialize-javascript@6.0.2: - resolution: {integrity: sha512-Saa1xPByTTq2gdeFZYLLo+RFE35NHZkAbqZeWNd3BpzppeVisAqpDjcp8dyf6uIvEqJRd46jemmyA4iFIeVk8g==} + serialize-javascript@7.0.5: + resolution: {integrity: sha512-F4LcB0UqUl1zErq+1nYEEzSHJnIwb3AF2XWB94b+afhrekOUijwooAYqFyRbjYkm2PAKBabx6oYv/xDxNi8IBw==} + engines: {node: '>=20.0.0'} set-function-length@1.2.2: resolution: {integrity: sha512-pgRc4hJ4/sNjWCSS9AmnS40x3bNMDTknHgL5UaMBTMyJnU90EgWh1Rz+MC9eFu4BuN/UwZjKQuY/1v3rM7HMfg==} @@ -4051,8 +4047,8 @@ packages: util@0.12.5: resolution: {integrity: sha512-kZf/K6hEIrWHI6XqOFUiiMa+79wE/D8Q+NCNAWclkyg3b4d2k7s0QGepNjiABc+aR3N1PAyHL7p6UcLY6LmrnA==} - uuid@11.1.0: - resolution: {integrity: sha512-0/A9rDy9P7cJ+8w1c9WD9V//9Wj15Ce2MPz8Ri6032usz+NfePxx5AcN3bN+r6ZL6jEo066/yNYB3tn4pQEx+A==} + uuid@11.1.1: + resolution: {integrity: sha512-vIYxrBCC/N/K+Js3qSN88go7kIfNPssr/hHCesKCQNAjmgvYS2oqr69kIufEG+O4+PfezOH4EbIeHCfFov8ZgQ==} hasBin: true uuid@8.3.2: @@ -4745,7 +4741,7 @@ snapshots: '@fluidframework/runtime-definitions': 2.53.1 '@fluidframework/runtime-utils': 2.53.1(debug@4.4.3) '@fluidframework/telemetry-utils': 2.53.1 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -4763,7 +4759,7 @@ snapshots: '@fluidframework/runtime-definitions': 2.63.0 '@fluidframework/runtime-utils': 2.63.0(debug@4.4.3) '@fluidframework/telemetry-utils': 2.63.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -4781,7 +4777,7 @@ snapshots: '@fluidframework/runtime-definitions': 2.74.0 '@fluidframework/runtime-utils': 2.74.0(debug@4.4.3) '@fluidframework/telemetry-utils': 2.74.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -4799,7 +4795,7 @@ snapshots: '@fluidframework/runtime-definitions': 2.83.0 '@fluidframework/runtime-utils': 2.83.0 '@fluidframework/telemetry-utils': 2.83.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -4816,7 +4812,7 @@ snapshots: '@fluidframework/runtime-definitions': 2.93.0 '@fluidframework/runtime-utils': 2.93.0 '@fluidframework/telemetry-utils': 2.93.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -5182,7 +5178,7 @@ snapshots: '@fluidframework/azure-service-utils@0.56.11': dependencies: '@fluidframework/protocol-definitions': 0.1026.0 - jsrsasign: 10.9.0 + jsrsasign: 11.1.2 '@fluidframework/cell@0.56.0': dependencies: @@ -5779,7 +5775,7 @@ snapshots: debug: 4.4.3(supports-color@8.1.1) double-ended-queue: 2.1.0-0 events_pkg: events@3.3.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -5797,7 +5793,7 @@ snapshots: debug: 4.4.3(supports-color@8.1.1) double-ended-queue: 2.1.0-0 events_pkg: events@3.3.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -5815,7 +5811,7 @@ snapshots: debug: 4.4.3(supports-color@8.1.1) double-ended-queue: 2.1.0-0 events_pkg: events@3.3.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -5833,7 +5829,7 @@ snapshots: debug: 4.4.3(supports-color@8.1.1) double-ended-queue: 2.1.0-0 events_pkg: events@3.3.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -5849,7 +5845,7 @@ snapshots: debug: 4.4.3(supports-color@8.1.1) double-ended-queue: 2.1.0-0 events_pkg: events@3.3.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -6353,7 +6349,7 @@ snapshots: double-ended-queue: 2.1.0-0 lz4js: 0.2.0 semver-ts: 1.0.3 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -6376,7 +6372,7 @@ snapshots: double-ended-queue: 2.1.0-0 lz4js: 0.2.0 semver-ts: 1.0.3 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -6399,7 +6395,7 @@ snapshots: double-ended-queue: 2.1.0-0 lz4js: 0.2.0 semver-ts: 1.0.3 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -6422,7 +6418,7 @@ snapshots: double-ended-queue: 2.1.0-0 lz4js: 0.2.0 semver-ts: 1.0.3 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -6444,7 +6440,7 @@ snapshots: double-ended-queue: 2.1.0-0 lz4js: 0.2.0 semver-ts: 1.0.3 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -7244,7 +7240,7 @@ snapshots: '@fluidframework/runtime-definitions': 2.53.1 '@fluidframework/runtime-utils': 2.53.1(debug@4.4.3) '@fluidframework/telemetry-utils': 2.53.1 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -7262,7 +7258,7 @@ snapshots: '@fluidframework/runtime-definitions': 2.63.0 '@fluidframework/runtime-utils': 2.63.0(debug@4.4.3) '@fluidframework/telemetry-utils': 2.63.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -7280,7 +7276,7 @@ snapshots: '@fluidframework/runtime-definitions': 2.74.0 '@fluidframework/runtime-utils': 2.74.0(debug@4.4.3) '@fluidframework/telemetry-utils': 2.74.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -7298,7 +7294,7 @@ snapshots: '@fluidframework/runtime-definitions': 2.83.0 '@fluidframework/runtime-utils': 2.83.0 '@fluidframework/telemetry-utils': 2.83.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -7315,7 +7311,7 @@ snapshots: '@fluidframework/runtime-definitions': 2.93.0 '@fluidframework/runtime-utils': 2.93.0 '@fluidframework/telemetry-utils': 2.93.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -7611,7 +7607,7 @@ snapshots: '@fluidframework/protocol-base': 0.1034.0 '@fluidframework/protocol-definitions': 0.1026.0 '@fluidframework/telemetry-utils': 0.56.11 - axios: 0.21.4(debug@4.4.3) + axios: 0.31.1(debug@4.4.3) uuid: 8.3.2 transitivePeerDependencies: - debug @@ -7627,7 +7623,7 @@ snapshots: '@fluidframework/protocol-base': 0.1036.5002 '@fluidframework/protocol-definitions': 0.1028.2000 '@fluidframework/telemetry-utils': 1.4.0 - axios: 0.28.1(debug@4.4.3) + axios: 0.31.1(debug@4.4.3) uuid: 8.3.2 transitivePeerDependencies: - debug @@ -7643,7 +7639,7 @@ snapshots: '@fluidframework/protocol-base': 0.1037.2001 '@fluidframework/protocol-definitions': 1.2.0 '@fluidframework/telemetry-utils': 2.0.0-internal.1.4.9 - axios: 0.26.1(debug@4.4.3) + axios: 0.31.1(debug@4.4.3) url: 0.11.4 uuid: 8.3.2 transitivePeerDependencies: @@ -7659,7 +7655,7 @@ snapshots: '@fluidframework/protocol-base': 0.1039.1000 '@fluidframework/protocol-definitions': 1.2.0 '@fluidframework/telemetry-utils': 2.0.0-internal.5.4.2 - axios: 0.26.1(debug@4.4.3) + axios: 0.31.1(debug@4.4.3) lz4js: 0.2.0 url: 0.11.4 uuid: 8.3.2 @@ -7677,7 +7673,7 @@ snapshots: '@fluidframework/protocol-base': 2.0.3 '@fluidframework/protocol-definitions': 3.2.0 '@fluidframework/telemetry-utils': 2.0.0-internal.7.0.3 - axios: 0.26.1(debug@4.4.3) + axios: 0.31.1(debug@4.4.3) lz4js: 0.2.0 url: 0.11.4 uuid: 9.0.1 @@ -7695,7 +7691,7 @@ snapshots: '@fluidframework/protocol-base': 4.0.1 '@fluidframework/protocol-definitions': 3.2.0 '@fluidframework/telemetry-utils': 2.0.0-rc.4.0.10 - axios: 1.15.0(debug@4.4.3) + axios: 1.16.0(debug@4.4.3) lz4js: 0.2.0 uuid: 9.0.1 transitivePeerDependencies: @@ -7709,7 +7705,7 @@ snapshots: '@fluidframework/core-utils': 2.0.0-rc.5.0.8 '@fluidframework/driver-definitions': 2.0.0-rc.5.0.8 '@fluidframework/telemetry-utils': 2.0.0-rc.5.0.8 - axios: 1.15.0(debug@4.4.3) + axios: 1.16.0(debug@4.4.3) lz4js: 0.2.0 uuid: 9.0.1 transitivePeerDependencies: @@ -7723,7 +7719,7 @@ snapshots: '@fluidframework/core-utils': 2.13.0 '@fluidframework/driver-definitions': 2.13.0 '@fluidframework/telemetry-utils': 2.13.0 - axios: 1.15.0(debug@4.4.3) + axios: 1.16.0(debug@4.4.3) lz4js: 0.2.0 uuid: 9.0.1 transitivePeerDependencies: @@ -7737,7 +7733,7 @@ snapshots: '@fluidframework/core-utils': 2.23.0 '@fluidframework/driver-definitions': 2.23.0 '@fluidframework/telemetry-utils': 2.23.0 - axios: 1.15.0(debug@4.4.3) + axios: 1.16.0(debug@4.4.3) lz4js: 0.2.0 uuid: 9.0.1 transitivePeerDependencies: @@ -7751,7 +7747,7 @@ snapshots: '@fluidframework/core-utils': 2.33.2 '@fluidframework/driver-definitions': 2.33.2 '@fluidframework/telemetry-utils': 2.33.2 - axios: 1.15.0(debug@4.4.3) + axios: 1.16.0(debug@4.4.3) lz4js: 0.2.0 uuid: 9.0.1 transitivePeerDependencies: @@ -7765,7 +7761,7 @@ snapshots: '@fluidframework/core-utils': 2.43.0 '@fluidframework/driver-definitions': 2.43.0 '@fluidframework/telemetry-utils': 2.43.0 - axios: 1.15.0(debug@4.4.3) + axios: 1.16.0(debug@4.4.3) lz4js: 0.2.0 uuid: 9.0.1 transitivePeerDependencies: @@ -7779,7 +7775,7 @@ snapshots: '@fluidframework/core-utils': 2.5.0 '@fluidframework/driver-definitions': 2.5.0 '@fluidframework/telemetry-utils': 2.5.0 - axios: 1.15.0(debug@4.4.3) + axios: 1.16.0(debug@4.4.3) lz4js: 0.2.0 uuid: 9.0.1 transitivePeerDependencies: @@ -7793,9 +7789,9 @@ snapshots: '@fluidframework/core-utils': 2.53.1 '@fluidframework/driver-definitions': 2.53.1 '@fluidframework/telemetry-utils': 2.53.1 - axios: 1.15.0(debug@4.4.3) + axios: 1.16.0(debug@4.4.3) lz4js: 0.2.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -7807,9 +7803,9 @@ snapshots: '@fluidframework/core-utils': 2.63.0 '@fluidframework/driver-definitions': 2.63.0 '@fluidframework/telemetry-utils': 2.63.0 - axios: 1.15.0(debug@4.4.3) + axios: 1.16.0(debug@4.4.3) lz4js: 0.2.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -7821,9 +7817,9 @@ snapshots: '@fluidframework/core-utils': 2.74.0 '@fluidframework/driver-definitions': 2.74.0 '@fluidframework/telemetry-utils': 2.74.0 - axios: 1.15.0(debug@4.4.3) + axios: 1.16.0(debug@4.4.3) lz4js: 0.2.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -7836,7 +7832,7 @@ snapshots: '@fluidframework/driver-definitions': 2.83.0 '@fluidframework/telemetry-utils': 2.83.0 lz4js: 0.2.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -7848,7 +7844,7 @@ snapshots: '@fluidframework/driver-definitions': 2.93.0 '@fluidframework/telemetry-utils': 2.93.0 lz4js: 0.2.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -7970,7 +7966,7 @@ snapshots: '@fluidframework/core-utils': 2.53.1 '@fluidframework/telemetry-utils': 2.53.1 '@tylerbu/sorted-btree-es6': 1.8.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -7981,7 +7977,7 @@ snapshots: '@fluidframework/core-utils': 2.63.0 '@fluidframework/telemetry-utils': 2.63.0 '@tylerbu/sorted-btree-es6': 1.8.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -7992,7 +7988,7 @@ snapshots: '@fluidframework/core-utils': 2.74.0 '@fluidframework/telemetry-utils': 2.74.0 '@tylerbu/sorted-btree-es6': 1.8.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -8003,7 +7999,7 @@ snapshots: '@fluidframework/core-utils': 2.83.0 '@fluidframework/telemetry-utils': 2.83.0 '@tylerbu/sorted-btree-es6': 2.1.1 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -8014,7 +8010,7 @@ snapshots: '@fluidframework/core-utils': 2.93.0 '@fluidframework/telemetry-utils': 2.93.0 '@tylerbu/sorted-btree-es6': 2.1.1 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -8032,7 +8028,7 @@ snapshots: '@fluidframework/server-services-client': 0.1034.0 '@fluidframework/server-services-core': 0.1034.0 '@fluidframework/server-test-utils': 0.1034.0 - jsrsasign: 10.9.0 + jsrsasign: 11.1.2 uuid: 8.3.2 transitivePeerDependencies: - bufferutil @@ -8080,7 +8076,7 @@ snapshots: '@fluidframework/server-services-client': 0.1037.2001 '@fluidframework/server-services-core': 0.1037.2001 '@fluidframework/server-test-utils': 0.1037.2001 - jsrsasign: 10.9.0 + jsrsasign: 11.1.2 uuid: 8.3.2 transitivePeerDependencies: - bufferutil @@ -8105,7 +8101,7 @@ snapshots: '@fluidframework/server-test-utils': 0.1039.1000 '@fluidframework/telemetry-utils': 2.0.0-internal.5.4.2 events: 3.3.0 - jsrsasign: 10.9.0 + jsrsasign: 11.1.2 url: 0.11.4 uuid: 8.3.2 transitivePeerDependencies: @@ -8132,7 +8128,7 @@ snapshots: '@fluidframework/server-test-utils': 2.0.3 '@fluidframework/telemetry-utils': 2.0.0-internal.7.0.3 events: 3.3.0 - jsrsasign: 10.9.0 + jsrsasign: 11.1.2 url: 0.11.4 uuid: 9.0.1 transitivePeerDependencies: @@ -8327,7 +8323,7 @@ snapshots: '@fluidframework/server-test-utils': 7.0.0 '@fluidframework/telemetry-utils': 2.53.1 jsrsasign: 11.1.2 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - bufferutil - debug @@ -8351,7 +8347,7 @@ snapshots: '@fluidframework/server-test-utils': 7.0.0 '@fluidframework/telemetry-utils': 2.63.0 jsrsasign: 11.1.2 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - bufferutil - debug @@ -8375,7 +8371,7 @@ snapshots: '@fluidframework/server-test-utils': 7.0.0 '@fluidframework/telemetry-utils': 2.74.0 jsrsasign: 11.1.2 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - bufferutil - debug @@ -8399,7 +8395,7 @@ snapshots: '@fluidframework/server-test-utils': 7.0.0 '@fluidframework/telemetry-utils': 2.83.0 jsrsasign: 11.1.2 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - bufferutil - encoding @@ -8422,7 +8418,7 @@ snapshots: '@fluidframework/server-test-utils': 7.0.0 '@fluidframework/telemetry-utils': 2.93.0 jsrsasign: 11.1.2 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - bufferutil - supports-color @@ -9926,7 +9922,7 @@ snapshots: '@fluidframework/odsp-driver-definitions': 2.53.1 '@fluidframework/telemetry-utils': 2.53.1 socket.io-client: 4.7.5 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - bufferutil - debug @@ -9946,7 +9942,7 @@ snapshots: '@fluidframework/odsp-driver-definitions': 2.63.0 '@fluidframework/telemetry-utils': 2.63.0 socket.io-client: 4.7.5 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - bufferutil - debug @@ -9966,7 +9962,7 @@ snapshots: '@fluidframework/odsp-driver-definitions': 2.74.0 '@fluidframework/telemetry-utils': 2.74.0 socket.io-client: 4.7.5 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - bufferutil - debug @@ -9986,7 +9982,7 @@ snapshots: '@fluidframework/odsp-driver-definitions': 2.83.0 '@fluidframework/telemetry-utils': 2.83.0 socket.io-client: 4.7.5 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - bufferutil - encoding @@ -10005,7 +10001,7 @@ snapshots: '@fluidframework/odsp-driver-definitions': 2.93.0 '@fluidframework/telemetry-utils': 2.93.0 socket.io-client: 4.8.3 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - bufferutil - supports-color @@ -10205,7 +10201,7 @@ snapshots: '@fluidframework/runtime-utils': 2.53.1(debug@4.4.3) '@fluidframework/shared-object-base': 2.53.1(debug@4.4.3) '@fluidframework/telemetry-utils': 2.53.1 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -10221,7 +10217,7 @@ snapshots: '@fluidframework/runtime-utils': 2.63.0(debug@4.4.3) '@fluidframework/shared-object-base': 2.63.0(debug@4.4.3) '@fluidframework/telemetry-utils': 2.63.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -10237,7 +10233,7 @@ snapshots: '@fluidframework/runtime-utils': 2.74.0(debug@4.4.3) '@fluidframework/shared-object-base': 2.74.0(debug@4.4.3) '@fluidframework/telemetry-utils': 2.74.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -10253,7 +10249,7 @@ snapshots: '@fluidframework/runtime-utils': 2.83.0 '@fluidframework/shared-object-base': 2.83.0 '@fluidframework/telemetry-utils': 2.83.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -10268,7 +10264,7 @@ snapshots: '@fluidframework/runtime-utils': 2.93.0 '@fluidframework/shared-object-base': 2.93.0 '@fluidframework/telemetry-utils': 2.93.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -11118,7 +11114,7 @@ snapshots: cross-fetch: 3.2.0 json-stringify-safe: 5.0.1 socket.io-client: 4.7.5 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - bufferutil - debug @@ -11139,7 +11135,7 @@ snapshots: cross-fetch: 3.2.0 json-stringify-safe: 5.0.1 socket.io-client: 4.7.5 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - bufferutil - debug @@ -11160,7 +11156,7 @@ snapshots: cross-fetch: 3.2.0 json-stringify-safe: 5.0.1 socket.io-client: 4.7.5 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - bufferutil - debug @@ -11873,7 +11869,7 @@ snapshots: '@fluidframework/shared-object-base': 2.53.1(debug@4.4.3) '@fluidframework/telemetry-utils': 2.53.1 double-ended-queue: 2.1.0-0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -11891,7 +11887,7 @@ snapshots: '@fluidframework/shared-object-base': 2.63.0(debug@4.4.3) '@fluidframework/telemetry-utils': 2.63.0 double-ended-queue: 2.1.0-0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -11909,7 +11905,7 @@ snapshots: '@fluidframework/shared-object-base': 2.74.0(debug@4.4.3) '@fluidframework/telemetry-utils': 2.74.0 double-ended-queue: 2.1.0-0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -11927,7 +11923,7 @@ snapshots: '@fluidframework/shared-object-base': 2.83.0 '@fluidframework/telemetry-utils': 2.83.0 double-ended-queue: 2.1.0-0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -11944,7 +11940,7 @@ snapshots: '@fluidframework/shared-object-base': 2.93.0 '@fluidframework/telemetry-utils': 2.93.0 double-ended-queue: 2.1.0-0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -12068,7 +12064,7 @@ snapshots: '@fluidframework/server-services-telemetry': 0.1034.0 '@types/semver': 6.2.7 async: 3.2.6 - axios: 0.21.4(debug@4.4.3) + axios: 0.31.1(debug@4.4.3) double-ended-queue: 2.1.0-0 json-stringify-safe: 5.0.1 lodash: 4.18.1 @@ -12093,7 +12089,7 @@ snapshots: '@fluidframework/server-services-telemetry': 0.1036.5002 '@types/semver': 6.2.7 async: 3.2.6 - axios: 0.28.1(debug@4.4.3) + axios: 0.31.1(debug@4.4.3) double-ended-queue: 2.1.0-0 json-stringify-safe: 5.0.1 lodash: 4.18.1 @@ -12118,7 +12114,7 @@ snapshots: '@fluidframework/server-services-telemetry': 0.1037.2001 '@types/semver': 6.2.7 async: 3.2.6 - axios: 0.26.1(debug@4.4.3) + axios: 0.31.1(debug@4.4.3) buffer: 6.0.3 double-ended-queue: 2.1.0-0 json-stringify-safe: 5.0.1 @@ -12145,7 +12141,7 @@ snapshots: '@types/semver': 6.2.7 assert: 2.1.0 async: 3.2.6 - axios: 0.26.1(debug@4.4.3) + axios: 0.31.1(debug@4.4.3) buffer: 6.0.3 double-ended-queue: 2.1.0-0 events: 3.3.0 @@ -12173,7 +12169,7 @@ snapshots: '@types/semver': 7.7.1 assert: 2.1.0 async: 3.2.6 - axios: 0.26.1(debug@4.4.3) + axios: 0.31.1(debug@4.4.3) buffer: 6.0.3 double-ended-queue: 2.1.0-0 events: 3.3.0 @@ -12201,7 +12197,7 @@ snapshots: '@types/semver': 7.7.1 assert: 2.1.0 async: 3.2.6 - axios: 1.15.0(debug@4.4.3) + axios: 1.16.0(debug@4.4.3) buffer: 6.0.3 double-ended-queue: 2.1.0-0 events: 3.3.0 @@ -12228,7 +12224,7 @@ snapshots: '@types/semver': 7.7.1 assert: 2.1.0 async: 3.2.6 - axios: 1.15.0(debug@4.4.3) + axios: 1.16.0(debug@4.4.3) buffer: 6.0.3 double-ended-queue: 2.1.0-0 events: 3.3.0 @@ -12255,7 +12251,7 @@ snapshots: '@types/semver': 7.7.1 assert: 2.1.0 async: 3.2.6 - axios: 1.15.0(debug@4.4.3) + axios: 1.16.0(debug@4.4.3) buffer: 6.0.3 double-ended-queue: 2.1.0-0 events: 3.3.0 @@ -12266,7 +12262,7 @@ snapshots: semver: 7.7.4 serialize-error: 8.1.0 sha.js: 2.4.12 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -12282,7 +12278,7 @@ snapshots: '@fluidframework/server-services-telemetry': 0.1034.0 '@fluidframework/server-test-utils': 0.1034.0 debug: 4.4.3(supports-color@8.1.1) - jsrsasign: 10.9.0 + jsrsasign: 11.1.2 uuid: 8.3.2 transitivePeerDependencies: - bufferutil @@ -12318,7 +12314,7 @@ snapshots: '@fluidframework/server-services-telemetry': 0.1037.2001 '@fluidframework/server-test-utils': 0.1037.2001 debug: 4.4.3(supports-color@8.1.1) - jsrsasign: 10.9.0 + jsrsasign: 11.1.2 uuid: 8.3.2 transitivePeerDependencies: - bufferutil @@ -12337,7 +12333,7 @@ snapshots: '@fluidframework/server-test-utils': 0.1039.1000 debug: 4.4.3(supports-color@8.1.1) events: 3.3.0 - jsrsasign: 10.9.0 + jsrsasign: 11.1.2 uuid: 8.3.2 transitivePeerDependencies: - bufferutil @@ -12356,7 +12352,7 @@ snapshots: '@fluidframework/server-test-utils': 2.0.3 debug: 4.4.3(supports-color@8.1.1) events: 3.3.0 - jsrsasign: 10.9.0 + jsrsasign: 11.1.2 uuid: 9.0.1 transitivePeerDependencies: - bufferutil @@ -12414,7 +12410,7 @@ snapshots: debug: 4.4.3(supports-color@8.1.1) events_pkg: events@3.3.0 jsrsasign: 11.1.2 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - bufferutil - supports-color @@ -12623,7 +12619,7 @@ snapshots: events: 3.3.0 lodash: 4.18.1 sillyname: 0.1.0 - uuid: 11.1.0 + uuid: 11.1.1 ws: 7.5.10 transitivePeerDependencies: - bufferutil @@ -12636,10 +12632,10 @@ snapshots: '@fluidframework/gitresources': 0.1034.0 '@fluidframework/protocol-base': 0.1034.0 '@fluidframework/protocol-definitions': 0.1026.0 - axios: 0.21.4(debug@4.4.3) + axios: 0.31.1(debug@4.4.3) crc-32: 1.2.0 debug: 4.4.3(supports-color@8.1.1) - jsrsasign: 10.9.0 + jsrsasign: 11.1.2 jwt-decode: 3.1.2 sillyname: 0.1.0 uuid: 8.3.2 @@ -12652,7 +12648,7 @@ snapshots: '@fluidframework/gitresources': 0.1036.5002 '@fluidframework/protocol-base': 0.1036.5002 '@fluidframework/protocol-definitions': 0.1028.2000 - axios: 0.28.1(debug@4.4.3) + axios: 0.31.1(debug@4.4.3) crc-32: 1.2.0 debug: 4.4.3(supports-color@8.1.1) json-stringify-safe: 5.0.1 @@ -12670,11 +12666,11 @@ snapshots: '@fluidframework/gitresources': 0.1037.2001 '@fluidframework/protocol-base': 0.1037.2001 '@fluidframework/protocol-definitions': 1.2.0 - axios: 0.26.1(debug@4.4.3) + axios: 0.31.1(debug@4.4.3) crc-32: 1.2.0 debug: 4.4.3(supports-color@8.1.1) json-stringify-safe: 5.0.1 - jsrsasign: 10.9.0 + jsrsasign: 11.1.2 jwt-decode: 3.1.2 querystring: 0.2.1 sillyname: 0.1.0 @@ -12688,11 +12684,11 @@ snapshots: '@fluidframework/gitresources': 0.1039.1000 '@fluidframework/protocol-base': 0.1039.1000 '@fluidframework/protocol-definitions': 1.2.0 - axios: 0.26.1(debug@4.4.3) + axios: 0.31.1(debug@4.4.3) crc-32: 1.2.0 debug: 4.4.3(supports-color@8.1.1) json-stringify-safe: 5.0.1 - jsrsasign: 10.9.0 + jsrsasign: 11.1.2 jwt-decode: 3.1.2 querystring: 0.2.1 sillyname: 0.1.0 @@ -12706,11 +12702,11 @@ snapshots: '@fluidframework/gitresources': 2.0.3 '@fluidframework/protocol-base': 2.0.3 '@fluidframework/protocol-definitions': 3.2.0 - axios: 0.26.1(debug@4.4.3) + axios: 0.31.1(debug@4.4.3) crc-32: 1.2.0 debug: 4.4.3(supports-color@8.1.1) json-stringify-safe: 5.0.1 - jsrsasign: 10.9.0 + jsrsasign: 11.1.2 jwt-decode: 3.1.2 querystring: 0.2.1 sillyname: 0.1.0 @@ -12724,7 +12720,7 @@ snapshots: '@fluidframework/gitresources': 4.0.1 '@fluidframework/protocol-base': 4.0.1 '@fluidframework/protocol-definitions': 3.2.0 - axios: 1.15.0(debug@4.4.3) + axios: 1.16.0(debug@4.4.3) crc-32: 1.2.0 debug: 4.4.3(supports-color@8.1.1) json-stringify-safe: 5.0.1 @@ -12741,7 +12737,7 @@ snapshots: '@fluidframework/gitresources': 5.0.0 '@fluidframework/protocol-base': 5.0.0 '@fluidframework/protocol-definitions': 3.2.0 - axios: 1.15.0(debug@4.4.3) + axios: 1.16.0(debug@4.4.3) crc-32: 1.2.0 debug: 4.4.3(supports-color@8.1.1) json-stringify-safe: 5.0.1 @@ -12758,14 +12754,14 @@ snapshots: '@fluidframework/gitresources': 7.0.0 '@fluidframework/protocol-base': 7.0.0 '@fluidframework/protocol-definitions': 3.2.0 - axios: 1.15.0(debug@4.4.3) + axios: 1.16.0(debug@4.4.3) crc-32: 1.2.0 debug: 4.4.3(supports-color@8.1.1) json-stringify-safe: 5.0.1 jsrsasign: 11.1.2 jwt-decode: 4.0.0 sillyname: 0.1.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -12948,7 +12944,7 @@ snapshots: json-stringify-safe: 5.0.1 path-browserify: 1.0.1 serialize-error: 8.1.0 - uuid: 11.1.0 + uuid: 11.1.1 '@fluidframework/server-test-utils@0.1034.0': dependencies: @@ -13090,7 +13086,7 @@ snapshots: ioredis-mock: 8.13.1(@types/ioredis-mock@8.2.7(ioredis@5.10.1))(ioredis@5.10.1) lodash: 4.18.1 string-hash: 1.1.3 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -13325,7 +13321,7 @@ snapshots: '@fluidframework/runtime-definitions': 2.53.1 '@fluidframework/runtime-utils': 2.53.1(debug@4.4.3) '@fluidframework/telemetry-utils': 2.53.1 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -13343,7 +13339,7 @@ snapshots: '@fluidframework/runtime-definitions': 2.63.0 '@fluidframework/runtime-utils': 2.63.0(debug@4.4.3) '@fluidframework/telemetry-utils': 2.63.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -13361,7 +13357,7 @@ snapshots: '@fluidframework/runtime-definitions': 2.74.0 '@fluidframework/runtime-utils': 2.74.0(debug@4.4.3) '@fluidframework/telemetry-utils': 2.74.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -13379,7 +13375,7 @@ snapshots: '@fluidframework/runtime-definitions': 2.83.0 '@fluidframework/runtime-utils': 2.83.0 '@fluidframework/telemetry-utils': 2.83.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -13396,7 +13392,7 @@ snapshots: '@fluidframework/runtime-definitions': 2.93.0 '@fluidframework/runtime-utils': 2.93.0 '@fluidframework/telemetry-utils': 2.93.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -13601,7 +13597,7 @@ snapshots: '@fluidframework/core-utils': 2.53.1 '@fluidframework/driver-definitions': 2.53.1 debug: 4.4.3(supports-color@8.1.1) - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -13612,7 +13608,7 @@ snapshots: '@fluidframework/core-utils': 2.63.0 '@fluidframework/driver-definitions': 2.63.0 debug: 4.4.3(supports-color@8.1.1) - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -13623,7 +13619,7 @@ snapshots: '@fluidframework/core-utils': 2.74.0 '@fluidframework/driver-definitions': 2.74.0 debug: 4.4.3(supports-color@8.1.1) - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -13634,7 +13630,7 @@ snapshots: '@fluidframework/core-utils': 2.83.0 '@fluidframework/driver-definitions': 2.83.0 debug: 4.4.3(supports-color@8.1.1) - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -13645,7 +13641,7 @@ snapshots: '@fluidframework/core-utils': 2.93.0 '@fluidframework/driver-definitions': 2.93.0 debug: 4.4.3(supports-color@8.1.1) - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -13702,7 +13698,7 @@ snapshots: '@fluidframework/runtime-definitions': 0.56.11 '@fluidframework/runtime-utils': 0.56.11 '@fluidframework/telemetry-utils': 0.56.11 - axios: 0.21.4(debug@4.4.3) + axios: 0.31.1(debug@4.4.3) uuid: 8.3.2 transitivePeerDependencies: - bufferutil @@ -13725,7 +13721,7 @@ snapshots: '@fluidframework/runtime-definitions': 1.4.0 '@fluidframework/runtime-utils': 1.4.0 '@fluidframework/telemetry-utils': 1.4.0 - axios: 0.28.1(debug@4.4.3) + axios: 0.31.1(debug@4.4.3) events: 3.3.0 jsrsasign: 11.1.2 uuid: 8.3.2 @@ -13750,8 +13746,8 @@ snapshots: '@fluidframework/runtime-definitions': 2.0.0-internal.1.4.9 '@fluidframework/runtime-utils': 2.0.0-internal.1.4.9 '@fluidframework/telemetry-utils': 2.0.0-internal.1.4.9 - axios: 0.26.1(debug@4.4.3) - jsrsasign: 10.9.0 + axios: 0.31.1(debug@4.4.3) + jsrsasign: 11.1.2 uuid: 8.3.2 transitivePeerDependencies: - bufferutil @@ -13774,9 +13770,9 @@ snapshots: '@fluidframework/runtime-definitions': 2.0.0-internal.5.4.2 '@fluidframework/runtime-utils': 2.0.0-internal.5.4.2(debug@4.4.3) '@fluidframework/telemetry-utils': 2.0.0-internal.5.4.2 - axios: 0.26.1(debug@4.4.3) + axios: 0.31.1(debug@4.4.3) events: 3.3.0 - jsrsasign: 10.9.0 + jsrsasign: 11.1.2 uuid: 8.3.2 transitivePeerDependencies: - bufferutil @@ -13799,9 +13795,9 @@ snapshots: '@fluidframework/runtime-definitions': 2.0.0-internal.7.0.3 '@fluidframework/runtime-utils': 2.0.0-internal.7.0.3(debug@4.4.3) '@fluidframework/telemetry-utils': 2.0.0-internal.7.0.3 - axios: 0.26.1(debug@4.4.3) + axios: 0.31.1(debug@4.4.3) events: 3.3.0 - jsrsasign: 10.9.0 + jsrsasign: 11.1.2 uuid: 9.0.1 transitivePeerDependencies: - bufferutil @@ -14218,7 +14214,7 @@ snapshots: best-random: 1.0.3 debug: 4.4.3(supports-color@8.1.1) mocha: 10.8.2 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - bufferutil - encoding @@ -14250,7 +14246,7 @@ snapshots: best-random: 1.0.3 debug: 4.4.3(supports-color@8.1.1) mocha: 10.8.2 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - bufferutil - encoding @@ -14282,7 +14278,7 @@ snapshots: best-random: 1.0.3 debug: 4.4.3(supports-color@8.1.1) mocha: 10.8.2 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - bufferutil - encoding @@ -14314,7 +14310,7 @@ snapshots: best-random: 1.0.3 debug: 4.4.3(supports-color@8.1.1) mocha: 10.8.2 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - bufferutil - encoding @@ -14345,7 +14341,7 @@ snapshots: '@fluidframework/telemetry-utils': 2.93.0 best-random: 1.0.3 debug: 4.4.3(supports-color@8.1.1) - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - bufferutil - supports-color @@ -14478,7 +14474,7 @@ snapshots: '@tylerbu/sorted-btree-es6': 1.8.0 '@types/ungap__structured-clone': 1.2.0 '@ungap/structured-clone': 1.3.0 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -14501,7 +14497,7 @@ snapshots: '@types/ungap__structured-clone': 1.2.0 '@ungap/structured-clone': 1.3.0 semver-ts: 1.0.3 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -14524,7 +14520,7 @@ snapshots: '@types/ungap__structured-clone': 1.2.0 '@ungap/structured-clone': 1.3.0 semver-ts: 1.0.3 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - debug - supports-color @@ -14547,7 +14543,7 @@ snapshots: '@types/ungap__structured-clone': 1.2.0 '@ungap/structured-clone': 1.3.0 semver-ts: 1.0.3 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -14568,7 +14564,7 @@ snapshots: '@sinclair/typebox': 0.34.49 '@tylerbu/sorted-btree-es6': 2.1.1 semver-ts: 1.0.3 - uuid: 11.1.0 + uuid: 11.1.1 transitivePeerDependencies: - supports-color @@ -14697,19 +14693,7 @@ snapshots: dependencies: possible-typed-array-names: 1.1.0 - axios@0.21.4(debug@4.4.3): - dependencies: - follow-redirects: 1.16.0(debug@4.4.3) - transitivePeerDependencies: - - debug - - axios@0.26.1(debug@4.4.3): - dependencies: - follow-redirects: 1.16.0(debug@4.4.3) - transitivePeerDependencies: - - debug - - axios@0.28.1(debug@4.4.3): + axios@0.31.1(debug@4.4.3): dependencies: follow-redirects: 1.16.0(debug@4.4.3) form-data: 4.0.5 @@ -14717,7 +14701,7 @@ snapshots: transitivePeerDependencies: - debug - axios@1.15.0(debug@4.4.3): + axios@1.16.0(debug@4.4.3): dependencies: follow-redirects: 1.16.0(debug@4.4.3) form-data: 4.0.5 @@ -15153,8 +15137,6 @@ snapshots: json-stringify-safe@5.0.1: {} - jsrsasign@10.9.0: {} - jsrsasign@11.1.2: {} jwt-decode@3.1.2: {} @@ -15205,7 +15187,7 @@ snapshots: log-symbols: 4.1.0 minimatch: 5.1.9 ms: 2.1.3 - serialize-javascript: 6.0.2 + serialize-javascript: 7.0.5 strip-json-comments: 3.1.1 supports-color: 8.1.1 workerpool: 6.5.1 @@ -15299,10 +15281,6 @@ snapshots: querystringify@2.2.0: {} - randombytes@2.1.0: - dependencies: - safe-buffer: 5.2.1 - readdirp@3.6.0: dependencies: picomatch: 2.3.2 @@ -15339,9 +15317,7 @@ snapshots: dependencies: type-fest: 0.20.2 - serialize-javascript@6.0.2: - dependencies: - randombytes: 2.1.0 + serialize-javascript@7.0.5: {} set-function-length@1.2.2: dependencies: @@ -15517,7 +15493,7 @@ snapshots: is-typed-array: 1.1.15 which-typed-array: 1.1.20 - uuid@11.1.0: {} + uuid@11.1.1: {} uuid@8.3.2: {} diff --git a/packages/test/test-version-utils/compat-workspaces/full/pnpm-workspace.yaml b/packages/test/test-version-utils/compat-workspaces/full/pnpm-workspace.yaml index 35a2d9beb45f..3cd3c225f41b 100644 --- a/packages/test/test-version-utils/compat-workspaces/full/pnpm-workspace.yaml +++ b/packages/test/test-version-utils/compat-workspaces/full/pnpm-workspace.yaml @@ -1,3 +1,6 @@ + +packages: + - '*' # This file is scaffolded by scripts/updateCompatVersions.ts. # The security settings below are intentional — do not relax them. minimumReleaseAge: 1440 @@ -11,9 +14,12 @@ minimumReleaseAgeExclude: - "@fluid-private/*" - "@fluid-tools/*" - "fluid-framework" +overrides: + axios@<1: ^0.31.1 + axios@>=1 <2: ^1.15.2 + jsrsasign@<12: ^11.1.1 + serialize-javascript@>=6 <7: ^7.0.5 + uuid@>=11 <12: ^11.1.1 # See: https://github.com/orgs/pnpm/discussions/11084 trustPolicy: off - -packages: - - '*' From 4360f39d46434500c44d0fe2d8a0fed7501917ac Mon Sep 17 00:00:00 2001 From: Alex Villarreal <716334+alexvy86@users.noreply.github.com> Date: Fri, 15 May 2026 16:03:00 -0500 Subject: [PATCH 2/3] Update comment --- .../compat-workspaces/full/pnpm-workspace.yaml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/packages/test/test-version-utils/compat-workspaces/full/pnpm-workspace.yaml b/packages/test/test-version-utils/compat-workspaces/full/pnpm-workspace.yaml index bf7cabb84037..93a041e1b988 100644 --- a/packages/test/test-version-utils/compat-workspaces/full/pnpm-workspace.yaml +++ b/packages/test/test-version-utils/compat-workspaces/full/pnpm-workspace.yaml @@ -1,7 +1,8 @@ +# Compat workspace configuration for full-version test matrices. packages: - '*' -# This file is scaffolded by scripts/updateCompatVersions.ts. + # The security settings below are intentional — do not relax them. minimumReleaseAge: 1440 From 7216bfcc4c04f815fda8a82ae494dea4fcd68c41 Mon Sep 17 00:00:00 2001 From: Alex Villarreal <716334+alexvy86@users.noreply.github.com> Date: Fri, 15 May 2026 16:16:53 -0500 Subject: [PATCH 3/3] Docs for overrides --- .../compat-workspaces/full/pnpm-workspace.yaml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/packages/test/test-version-utils/compat-workspaces/full/pnpm-workspace.yaml b/packages/test/test-version-utils/compat-workspaces/full/pnpm-workspace.yaml index 93a041e1b988..162d17301b6b 100644 --- a/packages/test/test-version-utils/compat-workspaces/full/pnpm-workspace.yaml +++ b/packages/test/test-version-utils/compat-workspaces/full/pnpm-workspace.yaml @@ -16,11 +16,17 @@ minimumReleaseAgeExclude: - "@fluid-tools/*" - "fluid-framework" overrides: + # axios, jsrsasign, serialize-javascript, and uuid, all overridden to address CVEs. + # Since this pnpm workspace deliberately installs older versions of Fluid packages, + # older dependency versions sometimes come in so we override them for security reasons. + # As we drop support for older versions of Fluid, these overrides can be reviewed. + # But as long as we support FF 1.x, these are probably all necessary. axios@<1: ^0.31.1 axios@>=1 <2: ^1.15.2 jsrsasign@<12: ^11.1.1 serialize-javascript@>=6 <7: ^7.0.5 uuid@>=11 <12: ^11.1.1 + # @fluidframework/test-utils>mocha: dropped here because this workspace only loads test-utils' primary export at runtime (see test-version-utils/src/testApi.ts) — it never invokes the legacy test-utils' bundled test runner. Removing mocha eliminates serialize-javascript@6.0.2 (GHSA-5c6j-r48x-rmvq) which would otherwise be pulled in transitively across all back-compat versions of @fluidframework/test-utils. "@fluidframework/test-utils>mocha": "-"