mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-09-09 08:22:11 +03:00
Two Dependabot alerts on the opencode plugin workspaces, both dev-scope: - #209 (high) toml@4.1.1 — prototype pollution via `__proto__` key-path desynchronization (GHSA-v5mp-jgw5-2x6j), pulled transitively by `effect` under `@opencode-ai/plugin`. Patched in 4.1.2. - #210 (low) esbuild@0.27.7 — arbitrary file read from the dev server on Windows (GHSA-g7r4-m6w7-qqqr), nested under `tsup`. Patched in 0.28.1. The top-level esbuild was already 0.28.1; only the nested copy lagged. Both are resolved with an `overrides` entry, reusing the pattern the v1 plugin already applies to esbuild. Neither package reaches the published runtime — they are build-time only — so this is hygiene, not an exposure fix. toml 4.1.1 -> 4.3.0, nested esbuild 0.27.7 dropped (single 0.28.2 remains). `npm install` reports 0 vulnerabilities in both workspaces; both plugins build and their suites pass (367 and 218 tests).
75 lines
2.4 KiB
JSON
75 lines
2.4 KiB
JSON
{
|
|
"name": "@omniroute/opencode-plugin",
|
|
"version": "0.2.1",
|
|
"description": "OpenCode plugin for the OmniRoute AI Gateway. Drives dynamic model discovery, /connect auth flow, and multi-instance OmniRoute providers via the official @opencode-ai/plugin contract.",
|
|
"type": "module",
|
|
"main": "./dist/index.js",
|
|
"types": "./dist/index.d.ts",
|
|
"exports": {
|
|
".": {
|
|
"types": "./dist/index.d.ts",
|
|
"import": "./dist/index.js"
|
|
},
|
|
"./runtime": {
|
|
"types": "./dist/index.d.ts",
|
|
"import": "./dist/index.js"
|
|
}
|
|
},
|
|
"files": [
|
|
"dist",
|
|
"README.md",
|
|
"LICENSE"
|
|
],
|
|
"scripts": {
|
|
"build": "tsup",
|
|
"clean": "rm -rf dist",
|
|
"test": "node --import tsx/esm --test tests/scaffold.test.ts tests/auth.test.ts tests/options-schema.test.ts tests/multi-instance.test.ts tests/fetch-interceptor.test.ts tests/telemetry.test.ts tests/provider.test.ts tests/gemini-sanitize.test.ts tests/combos.test.ts tests/config-shim.test.ts tests/features.test.ts tests/feature-defaults.test.ts tests/usable-combo.test.ts tests/disk-snapshot-perms.test.ts tests/fork-features.test.ts tests/auto-combo-context.test.ts tests/provider-id-routing.test.ts tests/management-read-token.test.ts tests/auto-sync.test.ts tests/model-allowlist.test.ts tests/log-level.test.ts tests/effort-tier-variants.test.ts tests/naming.test.ts tests/free-budget-magnitude.test.ts tests/models-fetcher.test.ts",
|
|
"prepublishOnly": "npm run clean && npm run build && npm test"
|
|
},
|
|
"keywords": [
|
|
"omniroute",
|
|
"opencode",
|
|
"opencode-plugin",
|
|
"ai-sdk",
|
|
"openai-compatible",
|
|
"provider",
|
|
"gemini",
|
|
"combos",
|
|
"mcp"
|
|
],
|
|
"author": "OmniRoute contributors",
|
|
"license": "MIT",
|
|
"repository": {
|
|
"type": "git",
|
|
"url": "https://github.com/diegosouzapw/OmniRoute.git",
|
|
"directory": "@omniroute/opencode-plugin"
|
|
},
|
|
"bugs": {
|
|
"url": "https://github.com/diegosouzapw/OmniRoute/issues"
|
|
},
|
|
"homepage": "https://github.com/diegosouzapw/OmniRoute/tree/main/%40omniroute/opencode-plugin#readme",
|
|
"engines": {
|
|
"node": ">=22.22.3"
|
|
},
|
|
"publishConfig": {
|
|
"access": "public"
|
|
},
|
|
"peerDependencies": {
|
|
"@opencode-ai/plugin": "*"
|
|
},
|
|
"dependencies": {
|
|
"zod": "^4.4.3"
|
|
},
|
|
"devDependencies": {
|
|
"@opencode-ai/plugin": "^1.15.6",
|
|
"@types/node": "^22.19.19",
|
|
"tsup": "^8.5.1",
|
|
"tsx": "^4.22.3",
|
|
"typescript": "^5.9.3"
|
|
},
|
|
"overrides": {
|
|
"esbuild": "^0.28.1",
|
|
"toml": "^4.1.2"
|
|
}
|
|
}
|