diff --git a/ui/pnpm-workspace.yaml b/ui/pnpm-workspace.yaml index cd3f7d25f2..551b8dd218 100644 --- a/ui/pnpm-workspace.yaml +++ b/ui/pnpm-workspace.yaml @@ -1,6 +1,3 @@ -# pnpm 11+ workspace config. .npmrc is auth/registry only; everything else lives here. -# Reference: https://pnpm.io/supply-chain-security - packages: [] # Refuse to install on Node/pnpm outside the `engines` block in package.json. @@ -28,7 +25,7 @@ overrides: # but not yet in the npm audit feed), fixed in 4.12.27. Not 4.12.29: it is # still inside StepSecurity's 7-day npm cooldown gate. "hono": "4.12.28" - "@hono/node-server": "1.19.14" + "@hono/node-server": "2.0.5" "@isaacs/brace-expansion": "5.0.1" "fast-xml-parser": "5.8.0" "serialize-javascript": "7.0.5" @@ -121,3 +118,6 @@ trustPolicyExclude: # Block transitive dependencies from using exotic specifiers (git URLs, tarballs). blockExoticSubdeps: true +minimumReleaseAgeExclude: + # Renovate security update: @hono/node-server@2.0.5 + - "@hono/node-server@2.0.5"