Skip to content

Upgrade Schemas to Comp/Con v3#40

Draft
Eliemer wants to merge 10 commits into
masterfrom
ev/v3-schemas
Draft

Upgrade Schemas to Comp/Con v3#40
Eliemer wants to merge 10 commits into
masterfrom
ev/v3-schemas

Conversation

@Eliemer
Copy link
Copy Markdown
Collaborator

@Eliemer Eliemer commented Apr 28, 2026

  • LCP Manifest
  • Core Bonus
  • Active Effects
    • Frames (traits, core systems)
    • Core bonuses
    • Eidolons
  • Actions
  • Frames
  • Weapons
  • NPCs
  • Eidolons
  • Tables
  • Lists
  • License Collection Format
  • Etc.
    • package bump

@Eliemer Eliemer self-assigned this Apr 28, 2026
@Eliemer Eliemer added enhancement New feature or request good first issue Good for newcomers labels Apr 28, 2026
Eliemer added 7 commits April 28, 2026 15:20
up to date, audited 439 packages in 1s

92 packages are looking for funding
  run `npm fund` for details

# npm audit report

flatted  <=3.4.1
Severity: high
flatted vulnerable to unbounded recursion DoS in parse() revive phase - GHSA-25h7-pfq9-p65f
Prototype Pollution via parse() in NodeJS flatted - GHSA-rf6f-7fwh-wjgh
fix available via `npm audit fix --force`
Will install eslint@10.2.1, which is a breaking change
node_modules/flatted
  flat-cache  1.3.1 || 2.0.0 - 2.0.1
  Depends on vulnerable versions of flatted
  node_modules/flat-cache
    file-entry-cache  4.0.0 - 5.0.1
    Depends on vulnerable versions of flat-cache
    node_modules/file-entry-cache
      eslint  4.0.0-alpha.0 - 7.14.0
      Depends on vulnerable versions of file-entry-cache
      Depends on vulnerable versions of inquirer
      node_modules/eslint

tmp  <=0.2.3
tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter - GHSA-52f5-9888-hmc6
fix available via `npm audit fix --force`
Will install eslint@10.2.1, which is a breaking change
node_modules/tmp
  external-editor  >=1.1.1
  Depends on vulnerable versions of tmp
  node_modules/external-editor
    inquirer  3.0.0 - 8.2.6 || 9.0.0 - 9.3.7
    Depends on vulnerable versions of external-editor
    node_modules/inquirer

uuid  <14.0.0
Severity: moderate
uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided - GHSA-w5hq-g745-h8pq
fix available via `npm audit fix --force`
Will install @vscode/vsce@2.25.0, which is a breaking change
node_modules/uuid
  @azure/msal-node  *
  Depends on vulnerable versions of uuid
  node_modules/@azure/msal-node
    @azure/identity  >=1.2.0-alpha.20200903.1
    Depends on vulnerable versions of @azure/msal-node
    node_modules/@azure/identity
      @vscode/vsce  >=2.25.1-0
      Depends on vulnerable versions of @azure/identity
      node_modules/@vscode/vsce

11 vulnerabilities (3 low, 4 moderate, 4 high)

To address all issues (including breaking changes), run:
  npm audit fix --force non-breaking changes
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request good first issue Good for newcomers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant