* fix(tools): evaluate calc expressions without expr-eval expr-eval has an unpatched critical advisory for code execution through toJSFunction(), which compiles expressions with new Function (GHSA-q9v2-7m5w-4693). The advisory covers every published version, so `bun run check:audit` fails on every branch and `bun audit fix` has nothing to upgrade to. The calc tool only ever called evaluate(), so the advisory's own vector was not reachable, but the dependency stays flagged and the evaluator's surface was far wider than the tool documents: random(), factorials, trigonometry, constants, strings, array indexing, property access and statement sequences all evaluated, while the documented ** operator did not parse at all, since expr-eval spells power as ^. Replace it with a recursive-descent evaluator for exactly the documented grammar. It compiles nothing, reaches no host object, and fixes **, which is right-associative and binds tighter than a leading sign, so -2 ** 2 is -4 as in ordinary notation. Non-finite results are still reported by the tool rather than the evaluator, so 1 / 0 keeps its "Produced Infinity" message. The tool had no tests; both the evaluator and the tool's JSON-array and error-reporting paths are covered now. * refactor(tools): parse calc expressions with jsep Replace the hand-written tokenizer and recursive-descent parser with jsep, a maintained zero-dependency expression parser with no advisory history, and keep only the tree walk: an allowlist of node types, arithmetic operators and the documented functions. Parsing, where the vulnerabilities in this class of library live, is no longer ours to maintain. Behaviour follows the parser rather than the previous hand-written precedence, so a leading sign now binds tighter than '**' and '-2 ** 2' is 4; the tests pin that alongside right-associativity. Parse errors keep jsep's own wording and character positions. * fix(tools): reject inherited names and fold long calc argument lists Two findings from review of this branch. The function lookup used `in`, so an inherited key such as `constructor(1)` passed the guard and then failed while destructuring a missing arity, reporting a TypeError instead of an unknown function; it now uses Object.hasOwn. min and max spread their arguments, which overflows the call stack on V8 at roughly 125k arguments, so they fold instead. Both paths are covered by tests.
225 lines
6.3 KiB
JSON
225 lines
6.3 KiB
JSON
{
|
|
"name": "@open-pencil/core",
|
|
"version": "0.15.1",
|
|
"license": "MIT",
|
|
"repository": {
|
|
"type": "git",
|
|
"url": "git+https://github.com/open-pencil/open-pencil.git",
|
|
"directory": "packages/core"
|
|
},
|
|
"files": [
|
|
"dist",
|
|
"src",
|
|
"assets"
|
|
],
|
|
"type": "module",
|
|
"sideEffects": false,
|
|
"main": "./dist/index.js",
|
|
"types": "./dist/index.d.ts",
|
|
"imports": {
|
|
"#core/*": "./src/*.ts"
|
|
},
|
|
"exports": {
|
|
"./package.json": "./package.json",
|
|
".": {
|
|
"types": "./dist/index.d.ts",
|
|
"import": "./dist/index.js",
|
|
"default": "./dist/index.js"
|
|
},
|
|
"./geometry": {
|
|
"types": "./dist/geometry/index.d.ts",
|
|
"import": "./dist/geometry/index.js",
|
|
"default": "./dist/geometry/index.js"
|
|
},
|
|
"./color": {
|
|
"types": "./dist/color/index.d.ts",
|
|
"import": "./dist/color/index.js",
|
|
"default": "./dist/color/index.js"
|
|
},
|
|
"./text": {
|
|
"types": "./dist/text/index.d.ts",
|
|
"import": "./dist/text/index.js",
|
|
"default": "./dist/text/index.js"
|
|
},
|
|
"./text/web-font/assets": {
|
|
"types": "./dist/text/web-font/assets.d.ts",
|
|
"import": "./dist/text/web-font/assets.js",
|
|
"default": "./dist/text/web-font/assets.js"
|
|
},
|
|
"./vector": {
|
|
"types": "./dist/vector/index.d.ts",
|
|
"import": "./dist/vector/index.js",
|
|
"default": "./dist/vector/index.js"
|
|
},
|
|
"./figma-api": {
|
|
"types": "./dist/figma-api/index.d.ts",
|
|
"import": "./dist/figma-api/index.js",
|
|
"default": "./dist/figma-api/index.js"
|
|
},
|
|
"./icons": {
|
|
"types": "./dist/icons/index.d.ts",
|
|
"import": "./dist/icons/index.js",
|
|
"default": "./dist/icons/index.js"
|
|
},
|
|
"./canvas": {
|
|
"types": "./dist/canvas/index.d.ts",
|
|
"import": "./dist/canvas/index.js",
|
|
"default": "./dist/canvas/index.js"
|
|
},
|
|
"./design-jsx": {
|
|
"types": "./dist/design-jsx/index.d.ts",
|
|
"import": "./dist/design-jsx/index.js",
|
|
"default": "./dist/design-jsx/index.js"
|
|
},
|
|
"./editor": {
|
|
"types": "./dist/editor/index.d.ts",
|
|
"import": "./dist/editor/index.js",
|
|
"default": "./dist/editor/index.js"
|
|
},
|
|
"./tools": {
|
|
"types": "./dist/tools/index.d.ts",
|
|
"import": "./dist/tools/index.js",
|
|
"default": "./dist/tools/index.js"
|
|
},
|
|
"./profiler": {
|
|
"types": "./dist/profiler/index.d.ts",
|
|
"import": "./dist/profiler/index.js",
|
|
"default": "./dist/profiler/index.js"
|
|
},
|
|
"./rpc": {
|
|
"types": "./dist/rpc/index.d.ts",
|
|
"import": "./dist/rpc/index.js",
|
|
"default": "./dist/rpc/index.js"
|
|
},
|
|
"./library": {
|
|
"bun": "./src/library/index.ts",
|
|
"types": "./dist/library/index.d.ts",
|
|
"import": "./dist/library/index.js",
|
|
"default": "./dist/library/index.js"
|
|
},
|
|
"./lint": {
|
|
"types": "./dist/lint/index.d.ts",
|
|
"import": "./dist/lint/index.js",
|
|
"default": "./dist/lint/index.js"
|
|
},
|
|
"./io": {
|
|
"types": "./dist/io/index.d.ts",
|
|
"import": "./dist/io/index.js",
|
|
"default": "./dist/io/index.js"
|
|
},
|
|
"./io/formats/fig": {
|
|
"types": "./dist/io/formats/fig/index.d.ts",
|
|
"import": "./dist/io/formats/fig/index.js",
|
|
"default": "./dist/io/formats/fig/index.js"
|
|
},
|
|
"./io/formats/jsx": {
|
|
"types": "./dist/io/formats/jsx/index.d.ts",
|
|
"import": "./dist/io/formats/jsx/index.js",
|
|
"default": "./dist/io/formats/jsx/index.js"
|
|
},
|
|
"./io/formats/raster": {
|
|
"types": "./dist/io/formats/raster/index.d.ts",
|
|
"import": "./dist/io/formats/raster/index.js",
|
|
"default": "./dist/io/formats/raster/index.js"
|
|
},
|
|
"./io/formats/svg": {
|
|
"types": "./dist/io/formats/svg/index.d.ts",
|
|
"import": "./dist/io/formats/svg/index.js",
|
|
"default": "./dist/io/formats/svg/index.js"
|
|
},
|
|
"./kiwi": {
|
|
"types": "./dist/kiwi/index.d.ts",
|
|
"import": "./dist/kiwi/index.js",
|
|
"default": "./dist/kiwi/index.js"
|
|
},
|
|
"./clipboard": {
|
|
"types": "./dist/clipboard.d.ts",
|
|
"import": "./dist/clipboard.js",
|
|
"default": "./dist/clipboard.js"
|
|
},
|
|
"./bytes": {
|
|
"bun": "./src/bytes/index.ts",
|
|
"types": "./dist/bytes/index.d.ts",
|
|
"import": "./dist/bytes/index.js",
|
|
"default": "./dist/bytes/index.js"
|
|
},
|
|
"./constants": {
|
|
"types": "./dist/constants.d.ts",
|
|
"import": "./dist/constants.js",
|
|
"default": "./dist/constants.js"
|
|
},
|
|
"./random": {
|
|
"types": "./dist/random.d.ts",
|
|
"import": "./dist/random.js",
|
|
"default": "./dist/random.js"
|
|
},
|
|
"./xpath": {
|
|
"types": "./dist/xpath.d.ts",
|
|
"import": "./dist/xpath.js",
|
|
"default": "./dist/xpath.js"
|
|
},
|
|
"./canvaskit": {
|
|
"types": "./dist/canvaskit.d.ts",
|
|
"import": "./dist/canvaskit.js",
|
|
"default": "./dist/canvaskit.js"
|
|
},
|
|
"./layout": {
|
|
"types": "./dist/layout.d.ts",
|
|
"import": "./dist/layout.js",
|
|
"default": "./dist/layout.js"
|
|
}
|
|
},
|
|
"publishConfig": {
|
|
"access": "public",
|
|
"provenance": true
|
|
},
|
|
"scripts": {
|
|
"build": "bunx tsdown --config tsdown.config.ts",
|
|
"prepublishOnly": "bun run build"
|
|
},
|
|
"dependencies": {
|
|
"@chenglou/pretext": "^0.0.7",
|
|
"@iconify/utils": "^3.1.4",
|
|
"@open-pencil/fig": "workspace:*",
|
|
"@open-pencil/kiwi": "workspace:*",
|
|
"@open-pencil/pen": "workspace:*",
|
|
"@open-pencil/scene-graph": "workspace:*",
|
|
"@tauri-apps/api": "^2.11.1",
|
|
"@valibot/to-json-schema": "^1.8.0",
|
|
"@xmldom/xmldom": "^0.9.11",
|
|
"acorn": "^8.18.0",
|
|
"canvaskit-wasm": "^0.41.1",
|
|
"culori": "^4.0.2",
|
|
"dedent": "^1.7.2",
|
|
"destr": "^2.0.5",
|
|
"diff": "^8.0.4",
|
|
"es-toolkit": "^1.51.0",
|
|
"fflate": "^0.8.3",
|
|
"fontoxpath": "^3.34.0",
|
|
"fzstd": "^0.1.1",
|
|
"js-base64": "^3.9.3",
|
|
"jsep": "^1.4.0",
|
|
"jspdf": "^4.2.1",
|
|
"nanoevents": "^9.1.0",
|
|
"ofetch": "^1.5.1",
|
|
"opentype.js": "^2.0.0",
|
|
"pptxgenjs": "^4.0.1",
|
|
"rbush": "^4.0.1",
|
|
"sucrase": "^3.35.1",
|
|
"svg-path-properties": "^2.0.2",
|
|
"svg2pdf.js": "^2.7.0",
|
|
"svgpath": "^2.6.0",
|
|
"twirlwind": "^0.3.0",
|
|
"unifont": "0.7.4",
|
|
"valibot": "^1.4.2",
|
|
"yoga-layout": "npm:@open-pencil/yoga-layout@3.3.0-grid.3"
|
|
},
|
|
"devDependencies": {
|
|
"@types/culori": "^4.0.1",
|
|
"@types/diff": "^8.0.0",
|
|
"@types/opentype.js": "^1.3.10",
|
|
"@types/rbush": "^4.0.0",
|
|
"typescript": "~5.8.3"
|
|
}
|
|
}
|