Skip to content

chore(deps): clear Dependabot security alerts - #95

Merged
JohnMcLear merged 1 commit into
mainfrom
chore/security-deps
Sep 21, 2026
Merged

JohnMcLear merged 1 commit into
mainfrom
chore/security-deps

Conversation

@JohnMcLear

Copy link
Copy Markdown
Member

Clears all 5 open Dependabot alerts on this repo (4 high, 1 medium). Both packages are development-scope transitives pulled in through pnpm-lock.yaml, not direct dependencies.

# severity package from to first patched
47 high js-yaml 4.1.1 4.3.2 4.3.2
46 high js-yaml 4.1.1 4.3.2 4.3.1
39 high brace-expansion 1.1.14 1.1.21 1.1.16
38 high js-yaml 4.1.1 4.3.2 4.3.0
37 medium js-yaml 4.1.1 4.3.2 4.2.0

pnpm update js-yaml brace-expansion --recursive leaves both on the vulnerable versions, so the fix is a pnpm.overrides entry scoped to the existing major (js-yaml@4, brace-expansion@1) plus a regenerated lockfile. Scoping to the major matters: a bare >=1.1.16 resolves every brace-expansion consumer — including minimatch@3 — up to 5.x.

Diff is the lockfile plus the override block; no other dependencies bumped, nothing user-facing changes.

Verified: pnpm install clean, pnpm run lint passes with 0 errors.

🤖 Generated with Claude Code

https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw

js-yaml and brace-expansion reach the dependency tree only transitively
via pnpm-lock.yaml (development scope), and a plain `pnpm update` does
not move them off the vulnerable versions. Pin the patched versions
inside their existing major with pnpm overrides and regenerate the
lockfile.

- js-yaml 4.1.1 -> 4.3.2
- brace-expansion 1.1.14 -> 1.1.21

Closes 5 open Dependabot alerts (4 high, 1 medium).
No runtime dependency changes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw
@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Patch vulnerable transitive development dependencies

🐞 Bug fix ⚙️ Configuration changes 🕐 Less than 10 minutes

Grey Divider

AI Description

• Adds major-scoped pnpm overrides for vulnerable development-only transitive dependencies.
• Upgrades js-yaml to 4.3.2 and brace-expansion to 1.1.21 in the lockfile.
• Clears five Dependabot alerts without changing runtime dependencies.
Diagram

graph TD
  Manifest["Package manifest"] -->|Scoped overrides| Resolver["pnpm resolver"] -->|Pins patched versions| Lockfile[(Lockfile)] -->|Installs dependencies| Tooling["Development tooling"]
Loading
High-Level Assessment

Major-scoped pnpm overrides are appropriate because ordinary recursive updates leave these transitive packages vulnerable. Direct dependencies would unnecessarily expose implementation details, while unscoped overrides could force incompatible major versions into consumers such as minimatch; the proposed approach minimizes dependency churn and runtime risk.

Files changed (2) +16 / -14

Other (2) +16 / -14
package.jsonAdd major-scoped security overrides +6/-0

Add major-scoped security overrides

• Adds pnpm overrides requiring patched js-yaml 4.x and brace-expansion 1.x releases. Major scoping prevents unrelated consumers from resolving incompatible newer majors.

package.json

pnpm-lock.yamlRegenerate lockfile with patched transitive versions +10/-14

Regenerate lockfile with patched transitive versions

• Records the overrides and replaces js-yaml 4.1.1 with 4.3.2 and brace-expansion 1.1.14 with 1.1.21. Existing development dependency consumers now resolve the patched releases without other dependency upgrades.

pnpm-lock.yaml

@qodo-free-for-open-source-projects

qodo-free-for-open-source-projects Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (1) 📎 Requirement gaps (0) 🎨 UX issues (0) 🔗 Cross-repo conflicts (0) 📜 Skill insights (0)

Grey Divider


Remediation recommended

1. Security fixes lack regression coverage 📘 Rule violation ▣ Testability
Description
The new pnpm.overrides entries update the vulnerable transitive packages, but no automated test or
audit assertion verifies that resolution remains on the patched versions. A later override or
lockfile change can reintroduce the affected versions without the lint check described by the PR
detecting the regression.
Code

package.json[R34-36]

+    "overrides": {
+      "js-yaml@4": "^4.3.2",
+      "brace-expansion@1": "^1.1.16"
Evidence
PR Compliance ID 565552 requires every explicitly described fix to include a regression test that
fails before the fix and passes afterward. The cited override block is the security fix, while the
PR changes contain no test or automated audit assertion covering the resolved package versions.

Rule 565552: Require regression test for every bug fix
package.json[33-37]
pnpm-lock.yaml[7-10]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The security dependency fix adds package overrides without an automated regression check proving that the vulnerable transitive versions are absent.
## Fix Focus Areas
- package.json[33-37]
- pnpm-lock.yaml[7-10]
## Recommended Fix
Add a named automated test or CI audit check that fails when `js-yaml` resolves below `4.3.2` or `brace-expansion` major version 1 resolves below `1.1.16`, and wire it into the repository's test workflow.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Tip of the day
💡 Did you know, you can add REVIEW.md to your repo root and Qodo follows it on every PR

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread package.json
Comment on lines +34 to +36
"overrides": {
"js-yaml@4": "^4.3.2",
"brace-expansion@1": "^1.1.16"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remediation recommended

1. Security fixes lack regression coverage 📘 Rule violation ▣ Testability

The new pnpm.overrides entries update the vulnerable transitive packages, but no automated test or
audit assertion verifies that resolution remains on the patched versions. A later override or
lockfile change can reintroduce the affected versions without the lint check described by the PR
detecting the regression.
Agent Prompt
## Issue description
The security dependency fix adds package overrides without an automated regression check proving that the vulnerable transitive versions are absent.

## Fix Focus Areas
- package.json[33-37]
- pnpm-lock.yaml[7-10]

## Recommended Fix
Add a named automated test or CI audit check that fails when `js-yaml` resolves below `4.3.2` or `brace-expansion` major version 1 resolves below `1.1.16`, and wire it into the repository's test workflow.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

@JohnMcLear
JohnMcLear merged commit c0c3cc3 into main Sep 21, 2026
4 checks passed
@JohnMcLear
JohnMcLear deleted the chore/security-deps branch September 21, 2026 15:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant