Files
OmniRoute/@omniroute/opencode-plugin/package.json
diegosouzapw 384ce49a4d chore(deps): patch toml and esbuild in the opencode plugin lockfiles
Two Dependabot alerts on the opencode plugin workspaces, both dev-scope:

- #209 (high) toml@4.1.1 — prototype pollution via `__proto__` key-path
  desynchronization (GHSA-v5mp-jgw5-2x6j), pulled transitively by `effect`
  under `@opencode-ai/plugin`. Patched in 4.1.2.
- #210 (low) esbuild@0.27.7 — arbitrary file read from the dev server on
  Windows (GHSA-g7r4-m6w7-qqqr), nested under `tsup`. Patched in 0.28.1.
  The top-level esbuild was already 0.28.1; only the nested copy lagged.

Both are resolved with an `overrides` entry, reusing the pattern the v1
plugin already applies to esbuild. Neither package reaches the published
runtime — they are build-time only — so this is hygiene, not an exposure fix.

toml 4.1.1 -> 4.3.0, nested esbuild 0.27.7 dropped (single 0.28.2 remains).
`npm install` reports 0 vulnerabilities in both workspaces; both plugins
build and their suites pass (367 and 218 tests).
2026-09-07 11:14:49 -03:00

75 lines
2.4 KiB
JSON

{
"name": "@omniroute/opencode-plugin",
"version": "0.2.1",
"description": "OpenCode plugin for the OmniRoute AI Gateway. Drives dynamic model discovery, /connect auth flow, and multi-instance OmniRoute providers via the official @opencode-ai/plugin contract.",
"type": "module",
"main": "./dist/index.js",
"types": "./dist/index.d.ts",
"exports": {
".": {
"types": "./dist/index.d.ts",
"import": "./dist/index.js"
},
"./runtime": {
"types": "./dist/index.d.ts",
"import": "./dist/index.js"
}
},
"files": [
"dist",
"README.md",
"LICENSE"
],
"scripts": {
"build": "tsup",
"clean": "rm -rf dist",
"test": "node --import tsx/esm --test tests/scaffold.test.ts tests/auth.test.ts tests/options-schema.test.ts tests/multi-instance.test.ts tests/fetch-interceptor.test.ts tests/telemetry.test.ts tests/provider.test.ts tests/gemini-sanitize.test.ts tests/combos.test.ts tests/config-shim.test.ts tests/features.test.ts tests/feature-defaults.test.ts tests/usable-combo.test.ts tests/disk-snapshot-perms.test.ts tests/fork-features.test.ts tests/auto-combo-context.test.ts tests/provider-id-routing.test.ts tests/management-read-token.test.ts tests/auto-sync.test.ts tests/model-allowlist.test.ts tests/log-level.test.ts tests/effort-tier-variants.test.ts tests/naming.test.ts tests/free-budget-magnitude.test.ts tests/models-fetcher.test.ts",
"prepublishOnly": "npm run clean && npm run build && npm test"
},
"keywords": [
"omniroute",
"opencode",
"opencode-plugin",
"ai-sdk",
"openai-compatible",
"provider",
"gemini",
"combos",
"mcp"
],
"author": "OmniRoute contributors",
"license": "MIT",
"repository": {
"type": "git",
"url": "https://github.com/diegosouzapw/OmniRoute.git",
"directory": "@omniroute/opencode-plugin"
},
"bugs": {
"url": "https://github.com/diegosouzapw/OmniRoute/issues"
},
"homepage": "https://github.com/diegosouzapw/OmniRoute/tree/main/%40omniroute/opencode-plugin#readme",
"engines": {
"node": ">=22.22.3"
},
"publishConfig": {
"access": "public"
},
"peerDependencies": {
"@opencode-ai/plugin": "*"
},
"dependencies": {
"zod": "^4.4.3"
},
"devDependencies": {
"@opencode-ai/plugin": "^1.15.6",
"@types/node": "^22.19.19",
"tsup": "^8.5.1",
"tsx": "^4.22.3",
"typescript": "^5.9.3"
},
"overrides": {
"esbuild": "^0.28.1",
"toml": "^4.1.2"
}
}