From 4da66cf04b11914f33cedd44b9788120bc45f1ad Mon Sep 17 00:00:00 2001 From: John McLear Date: Mon, 21 Sep 2026 16:08:47 +0100 Subject: [PATCH] chore(deps): clear Dependabot security alerts Force patched versions of the vulnerable transitive dev-scope dependencies via pnpm overrides, scoped to the affected major lines so nothing else moves: - js-yaml@4 -> ^4.3.2 (was 4.1.1) - brace-expansion@1 -> ^1.1.16 (was 1.1.14) js-yaml@5 (mocha) and brace-expansion@5 (minimatch@10) are unaffected. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw --- package.json | 6 ++++++ pnpm-lock.yaml | 24 ++++++++++-------------- 2 files changed, 16 insertions(+), 14 deletions(-) diff --git a/package.json b/package.json index fd988d5..aa2ebaa 100644 --- a/package.json +++ b/package.json @@ -32,5 +32,11 @@ }, "dependencies": { "ep_plugin_helpers": "^0.6.7" + }, + "pnpm": { + "overrides": { + "js-yaml@4": "^4.3.2", + "brace-expansion@1": "^1.1.16" + } } } diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index a518729..59d5d18 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -4,6 +4,10 @@ settings: autoInstallPeers: true excludeLinksFromLockfile: false +overrides: + js-yaml@4: ^4.3.2 + brace-expansion@1: ^1.1.16 + importers: .: @@ -316,8 +320,8 @@ packages: resolution: {integrity: sha512-BLrgEcRTwX2o6gGxGOCNyMvGSp35YofuYzw9h1IMTRmKqttAZZVU67bdb9Pr2vUHA8+j3i2tJfjO6C6+4myGTA==} engines: {node: 18 || 20 || >=22} - brace-expansion@1.1.14: - resolution: {integrity: sha512-MWPGfDxnyzKU7rNOW9SP/c50vi3xrmrua/+6hfPbCS2ABNWfx24vPidzvC7krjU/RTo235sV776ymlsMtGKj8g==} + brace-expansion@1.1.21: + resolution: {integrity: sha512-9zeA+KLZNNzglF2TPKRQEDyx6Yby7daAkuy8MiPzpXPsYDWi/DRM8jmwUDxokQjYqBpv5DgPiwD4h4ZZSy1Ujw==} brace-expansion@5.0.12: resolution: {integrity: sha512-YovQ3rzhaLMIrDjNDMkNS01tea93qhEhG5xy8f6+R0l+dw3Ki+5sCoIoI942iuLZTHWogWktgwVDhU09iNEimQ==} @@ -888,10 +892,6 @@ packages: isexe@2.0.0: resolution: {integrity: sha512-RHxMLp9lnKHGHRng9QFhRCMbYAcVpn69smSGcq3f36xjgVVWThj4qqLbTLlq7Ssj8B+fIQ1EuCEGI2lKsyQeIw==} - js-yaml@4.1.1: - resolution: {integrity: sha512-qQKT4zQxXl8lLwBtHMWwaTcGfFOZviOJet3Oy/xmGk2gZH677CJM9EvtfdSkgWcATZhj/55JZ0rmy3myCT5lsA==} - hasBin: true - js-yaml@4.3.2: resolution: {integrity: sha512-SFNOvSJ+Dgf/9An904Yx+CgSlIPCkIpao4qo51lpee25TIRejdH3rhR4EZMGoNx3/TP3O+wzWuiTFl4sqbltzA==} hasBin: true @@ -1323,7 +1323,7 @@ snapshots: globals: 13.24.0 ignore: 5.3.2 import-fresh: 3.3.1 - js-yaml: 4.1.1 + js-yaml: 4.3.2 minimatch: 3.1.5 strip-json-comments: 3.1.1 transitivePeerDependencies: @@ -1612,7 +1612,7 @@ snapshots: balanced-match@4.0.4: {} - brace-expansion@1.1.14: + brace-expansion@1.1.21: dependencies: balanced-match: 1.0.2 concat-map: 0.0.1 @@ -2004,7 +2004,7 @@ snapshots: imurmurhash: 0.1.4 is-glob: 4.0.3 is-path-inside: 3.0.3 - js-yaml: 4.1.1 + js-yaml: 4.3.2 json-stable-stringify-without-jsonify: 1.0.1 levn: 0.4.1 lodash.merge: 4.6.2 @@ -2322,10 +2322,6 @@ snapshots: isexe@2.0.0: {} - js-yaml@4.1.1: - dependencies: - argparse: 2.0.1 - js-yaml@4.3.2: dependencies: argparse: 2.0.1 @@ -2379,7 +2375,7 @@ snapshots: minimatch@3.1.5: dependencies: - brace-expansion: 1.1.14 + brace-expansion: 1.1.21 minimist@1.2.8: {}