verifyDepsBeforeRun: install packages: - frontend - packages/* overrides: react: "^19.2.4" react-dom: "^19.2.4" vite: "npm:rolldown-vite@7.3.1" form-data: ">=4.0.5" patchedDependencies: html-to-image@1.11.13: patches/html-to-image@1.11.13.patch peerDependencyRules: allowedVersions: vite: "7" minimumReleaseAge: 20160 minimumReleaseAgeExclude: - "@marimo-team/*" - yaml@2.8.3 - path-to-regexp@8.4.0 - oxlint@1.58.0 - "@oxlint/*" - lodash-es@4.18.1 # Renovate security update: dompurify@3.4.12 - dompurify@3.4.0 || 3.4.12 # Renovate security update: postcss@8.5.12 - postcss@8.5.10 || 8.5.12 - pyodide@314.0.0 # Renovate security update: js-cookie@3.0.7 - js-cookie@3.0.7 # Renovate security update: ws@8.21.0 - ws@8.21.0 blockExoticSubdeps: true trustPolicy: no-downgrade trustPolicyExclude: # Transitive/direct deps where the resolved version lacks SLSA provenance # but an earlier-published version had it. Verified no known takeovers as # of 2026-05-12 — these are publishing-pipeline changes, not incidents. - "@octokit/endpoint@9.0.6" - "@octokit/plugin-paginate-rest@9.2.2" - "@swc/core@1.12.14" - "@textea/json-viewer@4.0.1" - "chokidar@4.0.3" - "semver@5.7.2 || 6.3.1" - "tailwind-merge@2.6.0" - "undici@5.29.0" - "undici-types@6.21.0" onlyBuiltDependencies: []