pnpm audit --prod --audit-level=critical (the new CI gate) failed on vitest <3.2.6 (critical, arbitrary file read/execute via the UI server). Bump vitest + @vitest/coverage-v8 in-range across the workspace and add @vitest/coverage-v8 to every package that runs vitest but lacked it (core-audit, core-cms, core-eslint, core-testing, core-trpc, apps/cms, web-next, web-tanstack, turbo/generators) so 'pnpm test -- --coverage' works in every package. No compound test scripts exist, so the vitest-last pass-through concern does not apply. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
46 lines
1.3 KiB
JSON
46 lines
1.3 KiB
JSON
{
|
|
"name": "@repo/web-tanstack",
|
|
"private": true,
|
|
"version": "0.0.0",
|
|
"type": "module",
|
|
"scripts": {
|
|
"build": "echo 'placeholder — TanStack Start build configured in later plan'",
|
|
"dev": "echo 'placeholder'",
|
|
"lint": "eslint .",
|
|
"test": "vitest run --passWithNoTests",
|
|
"test:e2e": "playwright test",
|
|
"typecheck": "tsc --noEmit"
|
|
},
|
|
"dependencies": {
|
|
"@repo/blog": "workspace:*",
|
|
"@repo/core-api": "workspace:*",
|
|
"@repo/core-shared": "workspace:*",
|
|
"@repo/marketing-pages": "workspace:*",
|
|
"@repo/navigation": "workspace:*",
|
|
"@sentry/node": "^10.52.0",
|
|
"@sentry/react": "^10.52.0",
|
|
"@tanstack/react-query": "^5.66.0",
|
|
"@tanstack/react-router": "^1.120.0",
|
|
"@tanstack/start": "^1.120.0",
|
|
"react": "^19.0.0",
|
|
"react-dom": "^19.0.0",
|
|
"vinxi": "0.5.3"
|
|
},
|
|
"devDependencies": {
|
|
"@playwright/test": "^1.50.0",
|
|
"@repo/core-eslint": "workspace:*",
|
|
"@repo/core-testing": "workspace:*",
|
|
"@repo/core-typescript": "workspace:*",
|
|
"@sentry/vite-plugin": "^5.2.1",
|
|
"@testing-library/jest-dom": "^6.5.0",
|
|
"@testing-library/react": "^16.0.0",
|
|
"@testing-library/user-event": "^14.5.0",
|
|
"@types/node": "^22.0.0",
|
|
"@types/react": "^19.0.0",
|
|
"@types/react-dom": "^19.0.0",
|
|
"@vitest/coverage-v8": "^3.2.7",
|
|
"jsdom": "^25.0.0",
|
|
"vitest": "^3.2.7"
|
|
}
|
|
}
|