chore: 의존성 보안 취약점 정리 및 버전 업그레이드 - #151
Merged
Merged
Conversation
- 미사용 의존성 제거: next-auth, react-router-dom, shadcn-ui - 버전 업그레이드: axios ^1.18.0, swiper ^12.1.2, lodash ^4.17.23, postcss ^8.5.23 - resolutions 추가로 transitive 취약점 정리 - websocket-driver ^0.7.5: firebase Realtime DB의 critical 취약점 대응 - @grpc/grpc-js 1.9.16, protobufjs ^7.6.3, fast-uri ^3.1.6, nanoid ^3.3.18, postcss ^8.5.23 - @types/minimatch 5.1.2 고정 (6.0.0 stub 회귀 방지) 취약점 200건 → 53건 (남은 건 전부 next-pwa/workbox 빌드타임 툴체인) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
…pgrade # Conflicts: # yarn.lock
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
개요
Dependabot 취약점 대응을 위한 의존성 정리 및 버전 업그레이드입니다.
로컬
yarn audit기준 취약점 200건 → 53건으로 감소했고, 런타임 critical/high 취약점은 모두 해결했습니다.변경 내용
미사용 의존성 제거
next-auth— import·config·middleware·auth route 전부 없음 (미사용)react-router-dom— Next.js 앱이라 미사용shadcn-ui— CLI가dependencies에 잘못 포함됨 (런타임 import 없음)버전 업그레이드
axios^1.7.9→^1.18.0(axios 자체 CVE 대응)swiper^11.2.4→^12.1.2(프로토타입 오염 대응)lodash^4.17.21→^4.17.23postcss^8.4.38→^8.5.23resolutions 추가 (transitive 취약점 정리)
websocket-driver ^0.7.5— firebase Realtime DB의 critical 2건 포함 런타임 취약점 대응 ⭐@grpc/grpc-js 1.9.16,protobufjs ^7.6.3,fast-uri ^3.1.6,nanoid ^3.3.18,postcss ^8.5.23@types/minimatch 5.1.2고정 — lockfile 재생성 시 6.0.0 stub으로 드리프트되는 타입 회귀 방지남은 취약점 (53건)
전부
next-pwa → workbox-build/webpack-plugin빌드타임 툴체인(minimatch·brace-expansion·babel ReDoS 등)과@testing-library(테스트 전용)입니다. 실제 배포물·서버 런타임에는 영향 없음.@ducanh2912/next-pwa로 교체 시도했으나 workbox 7이@babel/preset-env를 더 끌고 와 오히려 91건으로 증가 → 원복@serwist/next마이그레이션 필요 (별도 진행)검증
tsc --noEmit통과next build통과 (18개 페이지 정상 생성, swiper 캐러셀 포함/mobile/main정상)🤖 Generated with Claude Code