Skip to content

Close 17 Dependabot alerts via refreshed pnpm overrides#802

Merged
sampottinger merged 1 commit into
mainfrom
tool/close-security
Jun 11, 2026
Merged

Close 17 Dependabot alerts via refreshed pnpm overrides#802
sampottinger merged 1 commit into
mainfrom
tool/close-security

Conversation

@sampottinger

Copy link
Copy Markdown
Contributor

All open alerts are dev/build-time-only transitive deps in editor/ (puppeteer, webpack/babel, grunt, eslint, jsdoc). Floor each to its first patched version through pnpm overrides:

ws >=8.20.1, serialize-javascript >=7.0.5, brace-expansion >=5.0.6,
@babel/plugin-transform-modules-systemjs >=7.29.4, fast-uri >=3.1.2,
basic-ftp >=5.3.1, ip-address >=10.1.1, lodash >=4.18.0,
picomatch >=2.3.2, flatted >=3.4.2

fast-uri/basic-ftp/picomatch are capped below their next major since their consumers (ajv, get-uri, micromatch) require the current major.

Migrate overrides from the deprecated package.json "pnpm" field to pnpm-workspace.yaml, and bump CI from pnpm@8 to pnpm@10.20.0 to match the packageManager field and lockfile v9 format so the overrides are honored during CI installs.

All open alerts are dev/build-time-only transitive deps in editor/
(puppeteer, webpack/babel, grunt, eslint, jsdoc). Floor each to its
first patched version through pnpm overrides:

  ws >=8.20.1, serialize-javascript >=7.0.5, brace-expansion >=5.0.6,
  @babel/plugin-transform-modules-systemjs >=7.29.4, fast-uri >=3.1.2,
  basic-ftp >=5.3.1, ip-address >=10.1.1, lodash >=4.18.0,
  picomatch >=2.3.2, flatted >=3.4.2

fast-uri/basic-ftp/picomatch are capped below their next major since
their consumers (ajv, get-uri, micromatch) require the current major.

Migrate overrides from the deprecated package.json "pnpm" field to
pnpm-workspace.yaml, and bump CI from pnpm@8 to pnpm@10.20.0 to match
the packageManager field and lockfile v9 format so the overrides are
honored during CI installs.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@sampottinger sampottinger merged commit 218f327 into main Jun 11, 2026
19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant