chore(deps): clear Dependabot security alerts - #110
Conversation
Force patched versions of the transitive development-scope deps js-yaml (>=4.3.2) and brace-expansion (>=1.1.16) via pnpm overrides and regenerate the lockfile. Both arrive through eslint / minimatch and are not direct dependencies, so a plain `pnpm update` cannot move them. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw
|
ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing |
PR Summary by QodoPatch vulnerable transitive development dependencies
AI Description
Diagram
High-Level Assessment
Files changed (2)
|
Code Review by Qodo🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)
Great, no issues found!Qodo reviewed your code and found no material issues that require reviewTip of the day💡 Did you know, you can add REVIEW.md to your repo root and Qodo follows it on every PR |
Clears all 5 open Dependabot alerts on this repo. All are transitive, development-scope only (they arrive via
eslint/minimatch), so nothing user-facing changes.pnpm update js-yaml brace-expansion --recursive --latestdoes not move them (neither is a direct dependency and the parents' ranges stay satisfied), so this adds scopedpnpm.overridesand regeneratespnpm-lock.yaml:js-yaml@^4→>=4.3.2 <5(lock: 4.1.1 → 4.3.2)brace-expansion@^1→>=1.1.16 <2(lock: 1.1.14 → 1.1.21)The overrides are version-scoped, so the already-patched
brace-expansion@5.x/js-yaml@5.xbranches of the tree are untouched. No other package versions change;pnpm auditgoes from 5 advisories to 0 andpnpm run lintpasses with 0 errors.🤖 Generated with Claude Code
https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw