Skip to content

Add air config for debugging - #231

Merged
DavidS-ovm merged 1 commit into
mainfrom
air
Apr 3, 2024
Merged

DavidS-ovm merged 1 commit into
mainfrom
air

Conversation

@DavidS-ovm

Copy link
Copy Markdown
Member

No description provided.

@DavidS-ovm
DavidS-ovm requested a review from getinnocuous April 3, 2024 14:21
Comment thread .air.toml Outdated
@DavidS-ovm
DavidS-ovm enabled auto-merge April 3, 2024 18:20
@DavidS-ovm
DavidS-ovm disabled auto-merge April 3, 2024 18:21
@DavidS-ovm
DavidS-ovm enabled auto-merge April 3, 2024 18:23
@DavidS-ovm
DavidS-ovm merged commit d59c340 into main Apr 3, 2024
@DavidS-ovm
DavidS-ovm deleted the air branch April 3, 2024 18:28
dylanratcliffe pushed a commit that referenced this pull request Sep 14, 2026
## Summary

- Close Dependabot #234 by forcing `decode-uri-component` to 0.5.0
(CVE-2026-45822).
- Close the Snyk Apache Thrift finding by replacing
`github.com/apache/thrift` to v0.24.0 (CVE-2026-41602); Arrow v15 still
pins 0.17.0.
- `image-size` (Dependabot #230 / #231) has no published fix. Dismiss
those alerts as Docusaurus build-only per `docs/COMPLIANCE.md`.

## Linear Ticket

Fixes:
[ENG-6446](https://linear.app/overmind/issue/ENG-6446/triage-and-patch-4-open-dependency-vulnerabilities)
— Triage and patch 4 open dependency vulnerabilities

- **Purpose**: Patch or ignore the four open dependency findings (3
GitHub Dependabot, 1 Snyk).

## Changes

- `pnpm-workspace.yaml`: security override
`decode-uri-component@<=0.4.2` → `0.5.0`, lockfile updated.
- `go.mod`: `replace github.com/apache/thrift =>
github.com/apache/thrift v0.24.0`.

Made with [Cursor](https://cursor.com)

Co-authored-by: Cursor <cursoragent@cursor.com>
GitOrigin-RevId: 22fdc6a49ad1c5a33b657c99c7e929af5a902956
tphoney added a commit that referenced this pull request Sep 14, 2026
## Summary

- Close Dependabot #234 by forcing `decode-uri-component` to 0.5.0
(CVE-2026-45822).
- Close the Snyk Apache Thrift finding by replacing
`github.com/apache/thrift` to v0.24.0 (CVE-2026-41602); Arrow v15 still
pins 0.17.0.
- `image-size` (Dependabot #230 / #231) has no published fix. Dismiss
those alerts as Docusaurus build-only per `docs/COMPLIANCE.md`.

## Linear Ticket

Fixes:
[ENG-6446](https://linear.app/overmind/issue/ENG-6446/triage-and-patch-4-open-dependency-vulnerabilities)
— Triage and patch 4 open dependency vulnerabilities

- **Purpose**: Patch or ignore the four open dependency findings (3
GitHub Dependabot, 1 Snyk).

## Changes

- `pnpm-workspace.yaml`: security override
`decode-uri-component@<=0.4.2` → `0.5.0`, lockfile updated.
- `go.mod`: `replace github.com/apache/thrift =>
github.com/apache/thrift v0.24.0`.

Made with [Cursor](https://cursor.com)

Co-authored-by: Cursor <cursoragent@cursor.com>
GitOrigin-RevId: 22fdc6a49ad1c5a33b657c99c7e929af5a902956
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant