869680a5a1
## What this does Resolves the remaining esbuild security alerts on packages we own, and upgrades the repo to **Vite 8** (which drops esbuild entirely in favour of rolldown/oxc). ### 1. esbuild → `^0.28.1` (security) - Raised the declared `esbuild` floor in `twenty-sdk` and the logic-function common-layer (both were `^0.25.0`, which can only resolve to a vulnerable version). These are our packages, so this is just declaring the patched version — clears Dependabot **#1467** and **#1468**. ### 2. Vite 7 → 8 - Bumped `vite` to `^8` in the 5 packages that declare it, and `@vitejs/plugin-react-swc` to `^4.3.1` (the only plugin that needed a bump for Vite 8; everything else already supports it). - `twenty-front` keeps esbuild minification, so esbuild is now an explicit (patched) devDependency there — Vite 8 no longer ships it. ### Two Vite-8 fallout fixes (bundler internals changed) - **Storybook tests:** added React to `optimizeDeps.include` so Vite's dep optimizer doesn't re-bundle React mid-run and break in-flight imports in browser-mode tests. - **`hex-rgb`:** it's ESM-only and broke rolldown's CJS interop (a default import resolved to the wrong thing under jest). Replaced its one use with a tiny inline hex→rgb parse and dropped the dependency. ## Verified Vite resolves to a single `8.0.16` with no esbuild in its tree. Builds pass on Vite 8/rolldown: `twenty-front` production build, the SDKs, and Storybook; the previously-failing front and storybook test jobs now pass; `yarn install --immutable` is clean. ## Note This doesn't close root alert **#1469** — esbuild is still pulled by other third-party tools (storybook, tsx, lingui, zapier, etc.) that haven't shipped a patched release. The vulnerable code path (esbuild's dev server) isn't used here, so that one is best dismissed as not-affected.
203 lines
5.0 KiB
JSON
203 lines
5.0 KiB
JSON
{
|
|
"name": "twenty-shared",
|
|
"private": true,
|
|
"sideEffects": false,
|
|
"main": "dist/index.cjs",
|
|
"module": "dist/index.mjs",
|
|
"types": "dist/index.d.ts",
|
|
"license": "AGPL-3.0",
|
|
"scripts": {
|
|
"build": "npx vite build"
|
|
},
|
|
"engines": {
|
|
"node": "^24.5.0",
|
|
"npm": "please-use-yarn",
|
|
"yarn": "^4.0.2"
|
|
},
|
|
"devDependencies": {
|
|
"@babel/preset-env": "^7.26.9",
|
|
"@babel/preset-typescript": "^7.24.6",
|
|
"@lingui/core": "^5.9.5",
|
|
"@prettier/sync": "^0.5.2",
|
|
"@swc/core": "^1.15.11",
|
|
"@swc/jest": "^0.2.39",
|
|
"@types/babel__preset-env": "^7",
|
|
"@types/handlebars": "^4.1.0",
|
|
"@types/jest": "^30.0.0",
|
|
"@types/lodash.camelcase": "^4.3.7",
|
|
"@types/lodash.escaperegexp": "^4.1.9",
|
|
"@types/qs": "6.9.16",
|
|
"@types/uuid": "^9.0.2",
|
|
"@typescript/native-preview": "^7.0.0-dev.20260116.1",
|
|
"babel-plugin-module-resolver": "^5.0.2",
|
|
"glob": "^11.1.0",
|
|
"jest": "29.7.0",
|
|
"jest-environment-jsdom": "30.0.0-beta.3",
|
|
"prettier": "^3.1.1",
|
|
"slash": "^5.1.0",
|
|
"tsc-alias": "^1.8.16",
|
|
"tsx": "^4.19.3",
|
|
"typescript": "^5.9.3",
|
|
"vite": "^8.0.0",
|
|
"vite-plugin-dts": "^4.5.4",
|
|
"vite-tsconfig-paths": "^4.2.1"
|
|
},
|
|
"dependencies": {
|
|
"@sniptt/guards": "^0.2.0",
|
|
"ai": "6.0.97",
|
|
"class-validator": "^0.14.0",
|
|
"expr-eval-fork": "3.0.3",
|
|
"handlebars": "^4.7.9",
|
|
"libphonenumber-js": "^1.10.26",
|
|
"lodash.camelcase": "^4.3.0",
|
|
"lodash.escaperegexp": "^4.1.2",
|
|
"microdiff": "^1.3.2",
|
|
"qs": "^6.15.2",
|
|
"react-router-dom": "^6.4.4",
|
|
"temporal-polyfill": "^0.3.0",
|
|
"transliteration": "^2.3.5",
|
|
"uuid": "^11.1.1",
|
|
"zod": "^4.1.11"
|
|
},
|
|
"exports": {
|
|
".": {
|
|
"types": "./dist/index.d.ts",
|
|
"import": "./dist/index.mjs",
|
|
"require": "./dist/index.cjs"
|
|
},
|
|
"./ai": {
|
|
"types": "./dist/ai/index.d.ts",
|
|
"import": "./dist/ai.mjs",
|
|
"require": "./dist/ai.cjs"
|
|
},
|
|
"./application": {
|
|
"types": "./dist/application/index.d.ts",
|
|
"import": "./dist/application.mjs",
|
|
"require": "./dist/application.cjs"
|
|
},
|
|
"./constants": {
|
|
"types": "./dist/constants/index.d.ts",
|
|
"import": "./dist/constants.mjs",
|
|
"require": "./dist/constants.cjs"
|
|
},
|
|
"./database-events": {
|
|
"types": "./dist/database-events/index.d.ts",
|
|
"import": "./dist/database-events.mjs",
|
|
"require": "./dist/database-events.cjs"
|
|
},
|
|
"./i18n": {
|
|
"types": "./dist/i18n/index.d.ts",
|
|
"import": "./dist/i18n.mjs",
|
|
"require": "./dist/i18n.cjs"
|
|
},
|
|
"./logic-function": {
|
|
"types": "./dist/logic-function/index.d.ts",
|
|
"import": "./dist/logic-function.mjs",
|
|
"require": "./dist/logic-function.cjs"
|
|
},
|
|
"./metadata": {
|
|
"types": "./dist/metadata/index.d.ts",
|
|
"import": "./dist/metadata.mjs",
|
|
"require": "./dist/metadata.cjs"
|
|
},
|
|
"./testing": {
|
|
"types": "./dist/testing/index.d.ts",
|
|
"import": "./dist/testing.mjs",
|
|
"require": "./dist/testing.cjs"
|
|
},
|
|
"./translations": {
|
|
"types": "./dist/translations/index.d.ts",
|
|
"import": "./dist/translations.mjs",
|
|
"require": "./dist/translations.cjs"
|
|
},
|
|
"./types": {
|
|
"types": "./dist/types/index.d.ts",
|
|
"import": "./dist/types.mjs",
|
|
"require": "./dist/types.cjs"
|
|
},
|
|
"./utils": {
|
|
"types": "./dist/utils/index.d.ts",
|
|
"import": "./dist/utils.mjs",
|
|
"require": "./dist/utils.cjs"
|
|
},
|
|
"./vite": {
|
|
"types": "./dist/vite/index.d.ts",
|
|
"import": "./dist/vite.mjs",
|
|
"require": "./dist/vite.cjs"
|
|
},
|
|
"./workflow": {
|
|
"types": "./dist/workflow/index.d.ts",
|
|
"import": "./dist/workflow.mjs",
|
|
"require": "./dist/workflow.cjs"
|
|
},
|
|
"./workspace": {
|
|
"types": "./dist/workspace/index.d.ts",
|
|
"import": "./dist/workspace.mjs",
|
|
"require": "./dist/workspace.cjs"
|
|
}
|
|
},
|
|
"files": [
|
|
"dist",
|
|
"ai",
|
|
"application",
|
|
"constants",
|
|
"database-events",
|
|
"i18n",
|
|
"logic-function",
|
|
"metadata",
|
|
"testing",
|
|
"translations",
|
|
"types",
|
|
"utils",
|
|
"vite",
|
|
"workflow",
|
|
"workspace"
|
|
],
|
|
"typesVersions": {
|
|
"*": {
|
|
"ai": [
|
|
"dist/ai/index.d.ts"
|
|
],
|
|
"application": [
|
|
"dist/application/index.d.ts"
|
|
],
|
|
"constants": [
|
|
"dist/constants/index.d.ts"
|
|
],
|
|
"database-events": [
|
|
"dist/database-events/index.d.ts"
|
|
],
|
|
"i18n": [
|
|
"dist/i18n/index.d.ts"
|
|
],
|
|
"logic-function": [
|
|
"dist/logic-function/index.d.ts"
|
|
],
|
|
"metadata": [
|
|
"dist/metadata/index.d.ts"
|
|
],
|
|
"testing": [
|
|
"dist/testing/index.d.ts"
|
|
],
|
|
"translations": [
|
|
"dist/translations/index.d.ts"
|
|
],
|
|
"types": [
|
|
"dist/types/index.d.ts"
|
|
],
|
|
"utils": [
|
|
"dist/utils/index.d.ts"
|
|
],
|
|
"vite": [
|
|
"dist/vite/index.d.ts"
|
|
],
|
|
"workflow": [
|
|
"dist/workflow/index.d.ts"
|
|
],
|
|
"workspace": [
|
|
"dist/workspace/index.d.ts"
|
|
]
|
|
}
|
|
}
|
|
}
|