- pnpm overrides pin every vulnerable transitive to its advisory's exact first-patched version, scoped to the advisory's own vulnerable range so no dependency is dragged across a major it didn't need (criticals: form-data 4.0.6, handlebars 4.7.9, protobufjs 7.5.5). - vitest < 3.2.6 is a critical (CVE fix floor) with no 0.x/1.x backport — forced major to ^3.2.6 in every package. Test scripts unify on `vitest run` (aci/ai ran bare watch mode). tools' vscode mock alias becomes absolute (vitest 3 dropped relative alias resolution). - packages/ai otel family 1.x → 2.x (core <2.8.0 advisory covers all 1.x): resourceFromAttributes, ATTR_* semconv, constructor spanProcessors. The previously-uncollectable telemetry suite now runs: ai 31 tests (was 16). - direct bumps: vite ^6.4.3 (site), esbuild ^0.25.8 (mcp), uuid ^11.1.1 (tools). packages/ai/package-lock.json deleted — stray npm lockfile in a pnpm workspace, carried 24 of the alerts. - ci: test step filtered @hanzo/tools but the package is @hanzo/cli-tools — the suite never ran in CI. Fixed; 87 tests now gate (behind the existing continue-on-error). pnpm 9 reads onlyBuiltDependencies from package.json, not pnpm-workspace.yaml — mirrored so native build scripts stay allowlisted. Verified: browser 243/243 + e2e 30/30 + build; aci 29/29; ai 31/31; cli-tools 87/87; site builds on vite 6; mcp builds on esbuild 0.25.
18 lines
423 B
TypeScript
18 lines
423 B
TypeScript
import { defineConfig } from 'vitest/config';
|
|
import path from 'path';
|
|
|
|
export default defineConfig({
|
|
test: {
|
|
globals: true,
|
|
environment: 'node',
|
|
setupFiles: ['./test/setup.ts'],
|
|
testTimeout: 10000,
|
|
hookTimeout: 10000
|
|
},
|
|
resolve: {
|
|
alias: {
|
|
// must be absolute — vitest 3 no longer resolves relative aliases
|
|
'vscode': path.resolve(__dirname, 'test/mocks/vscode.ts')
|
|
}
|
|
}
|
|
}); |