Skip to content

chore(deps): clear Dependabot security alerts - #115

Merged
JohnMcLear merged 1 commit into
masterfrom
chore/security-deps
Sep 21, 2026
Merged

JohnMcLear merged 1 commit into
masterfrom
chore/security-deps

Conversation

@JohnMcLear

Copy link
Copy Markdown
Member

Clears all 5 open Dependabot alerts on this repo. All are transitive, development-scope only (they arrive via eslint / minimatch), so nothing user-facing changes.

severity package first patched
high js-yaml 4.3.2
high js-yaml 4.3.1
high brace-expansion 1.1.16
high js-yaml 4.3.0
medium js-yaml 4.2.0

pnpm update js-yaml brace-expansion --recursive --latest does not move them (neither is a direct dependency and the parents' ranges stay satisfied), so this adds scoped pnpm.overrides and regenerates pnpm-lock.yaml:

  • js-yaml@^4 → >=4.3.2 <5 (lock: 4.1.1 → 4.3.2)
  • brace-expansion@^1 → >=1.1.16 <2 (lock: 1.1.14 → 1.1.21)

The overrides are version-scoped, so the already-patched brace-expansion@5.x / js-yaml@5.x branches of the tree are untouched. No other package versions change; pnpm audit goes from 5 advisories to 0 and pnpm run lint passes with 0 errors.

🤖 Generated with Claude Code

https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw

Force patched versions of the transitive development-scope deps
js-yaml (>=4.3.2) and brace-expansion (>=1.1.16) via pnpm overrides
and regenerate the lockfile. Both arrive through eslint /
minimatch and are not direct dependencies, so a plain
`pnpm update` cannot move them.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw
@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Patch vulnerable transitive development dependencies with pnpm overrides

🐞 Bug fix ⚙️ Configuration changes 🕐 Less than 10 minutes

Grey Divider

AI Description

• Pins secure js-yaml and brace-expansion versions through scoped pnpm overrides.
• Regenerates the lockfile without changing unaffected major-version dependency branches.
• Clears five development-only Dependabot alerts while preserving application behavior.
Diagram

graph TD
  A["package.json"] -->|scoped overrides| B["pnpm resolver"] -->|patched resolution| C["pnpm-lock.yaml"] -->|pinned dependencies| D["ESLint toolchain"]
Loading
High-Level Assessment

The scoped pnpm override approach is appropriate because the vulnerable packages are transitive and ordinary updates cannot move them while parent ranges remain satisfied. Major-version-specific selectors patch only affected 4.x and 1.x branches, avoiding unnecessary changes to already-secure newer branches.

Files changed (2) +16 / -14

Other (2) +16 / -14
package.jsonAdd scoped overrides for vulnerable transitive dependencies +6/-0

Add scoped overrides for vulnerable transitive dependencies

• Adds pnpm overrides requiring js-yaml 4.3.2 or newer within major version 4 and brace-expansion 1.1.16 or newer within major version 1. The scopes leave unrelated major-version branches unchanged.

package.json

pnpm-lock.yamlResolve patched js-yaml and brace-expansion versions +10/-14

Resolve patched js-yaml and brace-expansion versions

• Records the new overrides and replaces js-yaml 4.1.1 with 4.3.2 and brace-expansion 1.1.14 with 1.1.21. Existing consumers are rewired to the patched versions without changing other package versions.

pnpm-lock.yaml

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can add REVIEW.md to your repo root and Qodo follows it on every PR

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@JohnMcLear
JohnMcLear merged commit c401458 into master Sep 21, 2026
4 checks passed
@JohnMcLear
JohnMcLear deleted the chore/security-deps branch September 21, 2026 15:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant