chore(deps): clear Dependabot security alerts - #95
Conversation
js-yaml and brace-expansion reach the dependency tree only transitively via pnpm-lock.yaml (development scope), and a plain `pnpm update` does not move them off the vulnerable versions. Pin the patched versions inside their existing major with pnpm overrides and regenerate the lockfile. - js-yaml 4.1.1 -> 4.3.2 - brace-expansion 1.1.14 -> 1.1.21 Closes 5 open Dependabot alerts (4 high, 1 medium). No runtime dependency changes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw
|
ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing |
PR Summary by QodoPatch vulnerable transitive development dependencies
AI Description
Diagram
High-Level Assessment
Files changed (2)
|
Code Review by Qodo
1. Security fixes lack regression coverage
|
| "overrides": { | ||
| "js-yaml@4": "^4.3.2", | ||
| "brace-expansion@1": "^1.1.16" |
There was a problem hiding this comment.
1. Security fixes lack regression coverage 📘 Rule violation ▣ Testability
The new pnpm.overrides entries update the vulnerable transitive packages, but no automated test or audit assertion verifies that resolution remains on the patched versions. A later override or lockfile change can reintroduce the affected versions without the lint check described by the PR detecting the regression.
Agent Prompt
## Issue description
The security dependency fix adds package overrides without an automated regression check proving that the vulnerable transitive versions are absent.
## Fix Focus Areas
- package.json[33-37]
- pnpm-lock.yaml[7-10]
## Recommended Fix
Add a named automated test or CI audit check that fails when `js-yaml` resolves below `4.3.2` or `brace-expansion` major version 1 resolves below `1.1.16`, and wire it into the repository's test workflow.
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
Clears all 5 open Dependabot alerts on this repo (4 high, 1 medium). Both packages are development-scope transitives pulled in through
pnpm-lock.yaml, not direct dependencies.pnpm update js-yaml brace-expansion --recursiveleaves both on the vulnerable versions, so the fix is apnpm.overridesentry scoped to the existing major (js-yaml@4,brace-expansion@1) plus a regenerated lockfile. Scoping to the major matters: a bare>=1.1.16resolves everybrace-expansionconsumer — includingminimatch@3— up to 5.x.Diff is the lockfile plus the override block; no other dependencies bumped, nothing user-facing changes.
Verified:
pnpm installclean,pnpm run lintpasses with 0 errors.🤖 Generated with Claude Code
https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw