Skip to content

chore(deps): clear Dependabot security alerts - #94

Merged
JohnMcLear merged 1 commit into
mainfrom
chore/security-deps
Sep 21, 2026
Merged

JohnMcLear merged 1 commit into
mainfrom
chore/security-deps

Conversation

@JohnMcLear

Copy link
Copy Markdown
Member

Clears all 5 open Dependabot alerts on this repo. Both packages are development-scope transitives pulled in through pnpm-lock.yaml, not direct dependencies.

# severity package from to first patched
47 high js-yaml 4.1.1 4.3.2 4.3.2
46 high js-yaml 4.1.1 4.3.2 4.3.1
39 high brace-expansion 1.1.14 1.1.21 1.1.16
38 high js-yaml 4.1.1 4.3.2 4.3.0
37 medium js-yaml 4.1.1 4.3.2 4.2.0

pnpm update js-yaml brace-expansion --recursive leaves both on the vulnerable versions, so the fix is a pnpm.overrides entry scoped to the existing major (js-yaml@4, brace-expansion@1) plus a regenerated lockfile. Scoping to the major keeps brace-expansion@5 consumers untouched — a bare >=1.1.16 resolves all of them to 5.x.

Diff is the lockfile plus the override block; no other dependencies bumped, nothing user-facing changes.

Verified: pnpm install clean, pnpm run lint passes with 0 errors.

🤖 Generated with Claude Code

https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw

js-yaml and brace-expansion reach the dependency tree only transitively
via pnpm-lock.yaml (development scope), and a plain `pnpm update` does
not move them off the vulnerable versions. Pin the patched versions
inside their existing major with pnpm overrides and regenerate the
lockfile.

- js-yaml 4.1.1 -> 4.3.2 (3 high, 1 medium)
- brace-expansion 1.1.14 -> 1.1.21 (1 high)

No runtime dependency changes; `pnpm run lint` still passes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw
@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Clear Dependabot alerts with scoped pnpm overrides

🐞 Bug fix ⚙️ Configuration changes 🕐 Less than 10 minutes

Grey Divider

AI Description

• Force patched js-yaml 4.x and brace-expansion 1.x versions for development transitives.
• Regenerate the lockfile without changing runtime dependencies or brace-expansion 5.x consumers.
• Clear five Dependabot alerts while preserving existing major-version compatibility.
Diagram

graph TD
  A["package.json"] -->|defines| B["Scoped overrides"] -->|guides| C["pnpm resolver"] -->|regenerates| D["Lockfile"]
  D -->|pins 4.x| E["js-yaml 4.3.2"]
  D -->|pins 1.x| F["brace-expansion 1.1.21"]
Loading
High-Level Assessment

The scoped pnpm overrides are the appropriate approach because recursive updates do not move these transitive dependencies to patched releases. Major-specific selectors avoid affecting brace-expansion 5.x consumers, while the regenerated lockfile makes resolution reproducible; direct dependencies or broad overrides would add unnecessary coupling or compatibility risk.

Files changed (2) +16 / -14

Other (2) +16 / -14
package.jsonAdd major-scoped security overrides +6/-0

Add major-scoped security overrides

• Adds pnpm overrides requiring patched js-yaml 4.x and brace-expansion 1.x releases. The major-scoped selectors prevent unrelated consumers from being forced onto incompatible versions.

package.json

pnpm-lock.yamlResolve vulnerable transitives to patched releases +10/-14

Resolve vulnerable transitives to patched releases

• Records the override configuration and replaces js-yaml 4.1.1 with 4.3.2 and brace-expansion 1.1.14 with 1.1.21. Existing brace-expansion 5.x resolution remains unchanged.

pnpm-lock.yaml

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can add REVIEW.md to your repo root and Qodo follows it on every PR

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@JohnMcLear
JohnMcLear merged commit ba9a303 into main Sep 21, 2026
4 checks passed
@JohnMcLear
JohnMcLear deleted the chore/security-deps branch September 21, 2026 15:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant