Skip to content

chore(deps): clear Dependabot security alerts - #98

Merged
JohnMcLear merged 1 commit into
mainfrom
chore/security-deps
Sep 21, 2026
Merged

JohnMcLear merged 1 commit into
mainfrom
chore/security-deps

Conversation

@JohnMcLear

Copy link
Copy Markdown
Member

Clears all 5 open Dependabot alerts on this repo (4 high, 1 medium). Both packages are development-scope transitives pulled in through pnpm-lock.yaml, not direct dependencies.

# severity package from to first patched
44 high js-yaml 4.1.1 4.3.2 4.3.2
43 high js-yaml 4.1.1 4.3.2 4.3.1
37 high brace-expansion 1.1.14 1.1.21 1.1.16
36 high js-yaml 4.1.1 4.3.2 4.3.0
35 medium js-yaml 4.1.1 4.3.2 4.2.0

pnpm update js-yaml brace-expansion --recursive leaves both on the vulnerable versions, so the fix is a pnpm.overrides entry scoped to the existing major (js-yaml@4, brace-expansion@1) plus a regenerated lockfile. Scoping to the major matters: a bare >=1.1.16 resolves every brace-expansion consumer — including minimatch@3 — up to 5.x.

Diff is the lockfile plus the override block; no other dependencies bumped, nothing user-facing changes.

Verified: pnpm install clean, pnpm run lint passes with 0 errors.

🤖 Generated with Claude Code

https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw

js-yaml and brace-expansion reach the dependency tree only transitively
via pnpm-lock.yaml (development scope), and a plain `pnpm update` does
not move them off the vulnerable versions. Pin the patched versions
inside their existing major with pnpm overrides and regenerate the
lockfile.

- js-yaml 4.1.1 -> 4.3.2
- brace-expansion 1.1.14 -> 1.1.21

Closes 5 open Dependabot alerts (4 high, 1 medium).
No runtime dependency changes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw
@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Patch vulnerable development transitive dependencies

🐞 Bug fix ⚙️ Configuration changes 🕐 10-20 Minutes

Grey Divider

AI Description

• Add major-scoped overrides for vulnerable js-yaml and brace-expansion transitive dependencies.
• Regenerate the lockfile with patched versions while preventing cross-major upgrades.
• Clear five Dependabot alerts without affecting runtime dependencies.
Diagram

graph TD
  A["package.json"] -->|scoped overrides| B["pnpm resolver"] -->|regenerates| C["pnpm-lock.yaml"]
  C -->|pins 4.3.2| D["js-yaml 4"] --> E["ESLint tooling"]
  C -->|pins 1.1.21| F["brace-expansion 1"] --> G["minimatch 3"]
Loading
High-Level Assessment

Major-scoped pnpm overrides are the best fit because recursive updates leave these transitives vulnerable, while broad overrides could force minimatch 3 onto incompatible brace-expansion majors. Promoting transitives to direct dependencies would add unnecessary ownership without improving resolution control.

Files changed (2) +16 / -14

Other (2) +16 / -14
package.jsonAdd major-scoped security overrides +6/-0

Add major-scoped security overrides

• Adds pnpm overrides for js-yaml 4 and brace-expansion 1, ensuring patched transitive versions without permitting cross-major resolution.

package.json

pnpm-lock.yamlResolve patched transitive dependency versions +10/-14

Resolve patched transitive dependency versions

• Records the new overrides and replaces js-yaml 4.1.1 with 4.3.2 and brace-expansion 1.1.14 with 1.1.21. Existing consumers are rewired to the patched development-only versions.

pnpm-lock.yaml

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can add REVIEW.md to your repo root and Qodo follows it on every PR

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@JohnMcLear
JohnMcLear merged commit f56a549 into main Sep 21, 2026
4 checks passed
@JohnMcLear
JohnMcLear deleted the chore/security-deps branch September 21, 2026 15:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant