# pnpm 11+ workspace config. .npmrc is auth/registry only; everything else lives here. # Reference: https://pnpm.io/supply-chain-security packages: [] # Refuse to install on Node/pnpm outside the `engines` block in package.json. engineStrict: true # Default `pnpm add` to exact versions — matches package.json convention. saveExact: true # --- Dependency overrides --- overrides: "@react-types/shared": "3.26.0" "@internationalized/date": "3.10.0" "@react-aria/ssr>react": "19.2.7" "@react-aria/ssr>react-dom": "19.2.7" "@react-aria/visually-hidden>react": "19.2.7" "@react-aria/interactions>react": "19.2.7" "lodash": "4.18.1" # Next.js 16.3.3 requests sharp ^0.35.3; resolve 0.35.4 to fix # GHSA-rgj7-g3m4-5g8c (libheif). This override controls resolution; # keep it aligned with the direct dependency in package.json. "sharp": "0.35.4" "lodash-es": "4.18.1" # GHSA-88fw-hqm2-52qc (CORS reflects any Origin with credentials), CVE-2026-59896 # (hono/jsx SSR context leak) and the 4.12.34 batch: CORS ReDoS via # Access-Control-Request-Headers, `memo()` SSR output retained across requests, # Language middleware algorithmic DoS, Proxy Helper keeping `Connection` headers. # Node adapter 1.19.17 fixes serve-static path traversal via `%5C` on Windows # (1.19.15 was published without provenance and trips `trustPolicy: no-downgrade`). "hono": "4.12.34" "@hono/node-server": "1.19.17" "@isaacs/brace-expansion": "5.0.1" "fast-xml-parser": "5.8.0" "serialize-javascript": "7.0.5" # GHSA-6g55-p6wh-862q (sourceMappingURL path traversal reads arbitrary .map files) # and its incomplete-fix follow-up when `from` is unset, both closed in 8.5.23. "postcss": "8.5.23" "esbuild": "0.28.1" "rollup@>=4": "4.59.0" # GHSA-fx2h-pf6j-xcff (server.fs.deny bypass on Windows alternate paths, high) + # GHSA-v6wh-96g9-6wx3 (launch-editor NTLMv2 hash disclosure). Dev-only tooling # (vitest/@vitejs/plugin-react); consumers allow ^7 but never resolve past 7.3.2 # without a nudge. "vite@>=7 <8": "7.3.5" # GHSA-96hv-2xvq-fx4p (memory exhaustion DoS from tiny fragments, high) + # GHSA-58qx-3vcg-4xpx (uninitialized memory disclosure), both fixed in 8.21.0. # Not 8.21.1: it is still inside StepSecurity's 7-day npm cooldown gate. "ws@>=8 <9": "8.21.0" # Pulled by @sentry/server-utils bundler plugins (^2.1.0). Pinned because the # latest 2.3.1 is still inside StepSecurity's 7-day npm cooldown gate; safe to # drop this pin after 2026-07-20. "es-module-lexer": "2.3.0" # GHSA-4x5r-pxfx-6jf8 (arbitrary file read via sourceMappingURL comment, low), # fixed in 7.29.1. An override instead of `pnpm update` so the rest of the # babel/browserslist subtree keeps its existing lockfile resolutions. "@babel/core": "7.29.7" # browserslist 4.28.7 fixes unbounded query-result cache growth (OOM) and an # uncaught crash / prototype write from untrusted browserslist-stats.json. # caniuse-lite and baseline-browser-mapping stay pinned so the babel subtree # does not float past StepSecurity's 7-day npm cooldown gate. "browserslist": "4.28.7" "caniuse-lite": "1.0.30001792" "baseline-browser-mapping": "2.10.29" "minimatch@<4": "3.1.4" "minimatch@>=9 <10": "9.0.7" "minimatch@>=10": "10.2.3" "ajv@<7": "6.14.0" "ajv@>=8": "8.18.0" # 6.16.0 fixes the bracket-key comma array-limit bypass and DoS via an # attacker-controlled isBuffer. "qs": "6.16.0" # 8.2.2 dropped provenance attestation; 8.3.1+ restored it. Pinned to skip 8.2.2 # under `trustPolicy: no-downgrade`. "express-rate-limit": "8.5.1" # GHSA-w5hq-g745-h8pq: missing bounds check in v3/v5/v6 with buf, fixed in # 11.1.1. Transitive consumers (@sentry/webpack-plugin@9, @langchain/langgraph@10) # use the random v4 generator only, so the bug isn't reachable in practice, # but the override unifies the tree on a patched version. "uuid": "11.1.1" # GHSA-vxr8-fq34-vvx9 (+ several related XSS sanitization bypasses): DOMPurify < 3.4.9, # pulled in transitively via streamdown > mermaid and posthog-js. 3.4.11 closed # GHSA-cmwh-pvxp-8882 (permanent ALLOWED_ATTR pollution via setConfig()); 3.4.13 # also closes the CUSTOM_ELEMENT_HANDLING afterSanitizeElements bypass and the # IN_PLACE hook removal that left a detached subtree executable. "dompurify": "3.4.13" # Advisories flagged by `pnpm audit` on 2026-09-08. Every pin below is the # oldest patched release and was published more than 7 days before that date, # so it clears StepSecurity's npm cooldown gate. # brace-expansion: three DoS advisories (exponential `{}` expansion, unbounded # expansion length OOM, unbounded intermediate arrays bypassing the # CVE-2026-14257 mitigation). 1.x via eslint > minimatch, 5.x via @sentry > glob. "brace-expansion@<2": "1.1.18" "brace-expansion@>=5": "5.0.9" # fast-uri (via ajv): host confusion through backslash authority delimiters, # failed IDN canonicalization and percent-encoded scheme normalization, plus SSRF # via malformed IPv6 normalization and repeated hostname percent-decoding. "fast-uri": "3.1.6" # ip-address (via express-rate-limit): SSRF / trust-boundary bypasses from # leading-zero octets, CIDR suffixes and IPv4-mapped / NAT64 misclassification. "ip-address": "10.3.1" # mermaid (via streamdown): prototype pollution in config APIs and Architecture # diagrams, CSS injection into sibling elements, XY Chart infinite loop and # radar diagram DoS. "mermaid": "11.16.1" # body-parser (via express): invalid `limit` silently disabled size enforcement. "body-parser": "2.3.0" # @humanfs/node (via eslint): recursive copy followed symlinks outside the tree. "@humanfs/node": "0.16.8" # js-yaml: quadratic CPU in `!!omap` resolution (CVE-2026-59870 not backported # to 4.3.0). Direct dep is already 4.3.1; the override lifts eslint's copy too. "js-yaml": "4.3.1" # --- Level 1: Minimum Release Age --- # Packages must be published for at least 1 day before they can be installed. # Prevents installing compromised packages during the detection window. minimumReleaseAge: 1440 # Bypasses the minimum release age for specific packages. # Use ONLY for emergency patches (e.g., critical CVE fixes) that cannot wait 24h. # This should be ephemeral — remove the entry once the package meets the age threshold. # minimumReleaseAgeExclude: # --- Level 2: Explicit Build Script Allow-list --- # Only these packages may run install/postinstall lifecycle scripts. # Any unlisted package with lifecycle scripts fails the install. strictDepBuilds: true allowBuilds: # sharp: Native image processing (libvips). Installs platform-specific pre-built binary or compiles from source. sharp: true # @sentry/cli: Downloads the sentry-cli native binary for the current platform. Validates integrity via SHA256. "@sentry/cli": true # esbuild: Go binary. Downloads the pre-compiled binary matching the current platform/architecture. esbuild: true # unrs-resolver: Rust module resolver (NAPI-RS). Verifies the correct native binding is available for the platform. unrs-resolver: true # msw: Copies mockServiceWorker.js into the directories listed in package.json's `msw.workerDirectory` (here: `public/`) so the runtime worker stays in sync with the installed msw version. Pure file copy — no native binary, no network access. Required for vitest browser tests to intercept fetches via the service worker. msw: true # core-js: transitive dep of posthog-js. Its postinstall only prints a funding # banner — no native binary is needed for the feedback survey. Deny the script. core-js: false # --- Level 3: Trust Policy + Exotic Subdeps --- # Fail when a package's trust evidence is downgraded (e.g., new publisher). trustPolicy: no-downgrade # False positives — packages that don't publish provenance for real releases. # Pin to the version range that lacks provenance so a bump fails until reviewed. trustPolicyExclude: # next-auth: only one one-off manual test release (`0.0.0-manual.2824fa11`) has # provenance; real beta/stable releases don't. Scoped to current beta line. - "next-auth@5.0.0-beta.32" # semver: legacy major 6.x never had provenance (added in 7.5.1+). Pinned # to the exact 6.x version pulled transitively (via @babel/helper-compilation-targets). - "semver@6.3.1" # Block transitive dependencies from using exotic specifiers (git URLs, tarballs). blockExoticSubdeps: true