Skip to content

chore(deps): clear Dependabot security alerts - #110

Merged
JohnMcLear merged 1 commit into
mainfrom
chore/security-deps
Sep 21, 2026
Merged

JohnMcLear merged 1 commit into
mainfrom
chore/security-deps

Conversation

@JohnMcLear

Copy link
Copy Markdown
Member

Clears all 5 open Dependabot alerts on this repo. All are transitive, development-scope only (they arrive via eslint / minimatch), so nothing user-facing changes.

severity package first patched
high js-yaml 4.3.2
high js-yaml 4.3.1
high brace-expansion 1.1.16
high js-yaml 4.3.0
medium js-yaml 4.2.0

pnpm update js-yaml brace-expansion --recursive --latest does not move them (neither is a direct dependency and the parents' ranges stay satisfied), so this adds scoped pnpm.overrides and regenerates pnpm-lock.yaml:

  • js-yaml@^4 → >=4.3.2 <5 (lock: 4.1.1 → 4.3.2)
  • brace-expansion@^1 → >=1.1.16 <2 (lock: 1.1.14 → 1.1.21)

The overrides are version-scoped, so the already-patched brace-expansion@5.x / js-yaml@5.x branches of the tree are untouched. No other package versions change; pnpm audit goes from 5 advisories to 0 and pnpm run lint passes with 0 errors.

🤖 Generated with Claude Code

https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw

Force patched versions of the transitive development-scope deps
js-yaml (>=4.3.2) and brace-expansion (>=1.1.16) via pnpm overrides
and regenerate the lockfile. Both arrive through eslint /
minimatch and are not direct dependencies, so a plain
`pnpm update` cannot move them.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw
@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Patch vulnerable transitive development dependencies

⚙️ Configuration changes 🐞 Bug fix 🕐 Less than 10 minutes

Grey Divider

AI Description

• Adds scoped pnpm overrides for vulnerable development-only transitive dependencies.
• Regenerates the lockfile with patched js-yaml and brace-expansion releases.
• Preserves unaffected major-version branches and production behavior.
Diagram

graph TD
  manifest["package.json"] -->|scoped overrides| resolver["pnpm resolver"] -->|ESLint path| eslint["ESLint dependencies"] --> yaml["js-yaml 4.3.2"]
  resolver -->|minimatch path| minimatch["minimatch dependencies"] --> brace["brace-expansion 1.1.21"]
  resolver -->|writes resolutions| lockfile["pnpm-lock.yaml"]
Loading
High-Level Assessment

Scoped pnpm overrides are the most targeted approach because both vulnerable packages are transitive and remain within their parents' accepted ranges. A plain recursive update cannot move them, while upgrading parent packages or adding direct dependencies would introduce broader or misleading dependency changes. Major-version-scoped constraints also leave already-patched v5 branches untouched.

Files changed (2) +16 / -14

Other (2) +16 / -14
package.jsonAdd scoped overrides for vulnerable transitive packages +6/-0

Add scoped overrides for vulnerable transitive packages

• Adds pnpm overrides requiring patched js-yaml 4.x and brace-expansion 1.x releases. The constraints remain within each dependency's existing major version to avoid affecting unrelated branches.

package.json

pnpm-lock.yamlResolve transitive dependencies to patched releases +10/-14

Resolve transitive dependencies to patched releases

• Records the new override constraints and replaces js-yaml 4.1.1 with 4.3.2 and brace-expansion 1.1.14 with 1.1.21. Existing newer major-version resolutions remain unchanged.

pnpm-lock.yaml

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can add REVIEW.md to your repo root and Qodo follows it on every PR

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@JohnMcLear
JohnMcLear merged commit 322d879 into main Sep 21, 2026
4 checks passed
@JohnMcLear
JohnMcLear deleted the chore/security-deps branch September 21, 2026 15:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant