Skip to content

chore(deps): apply security overrides for h3, tar, devalue, diff#968

Merged
justinvdm merged 1 commit intomainfrom
security-deps-2025-jan-21
Jan 21, 2026
Merged

chore(deps): apply security overrides for h3, tar, devalue, diff#968
justinvdm merged 1 commit intomainfrom
security-deps-2025-jan-21

Conversation

@justinvdm
Copy link
Copy Markdown
Collaborator

Addresses detected vulnerabilities in transitive dependencies by applying overrides in the monorepo root.

Vulnerabilities Addressed

  • h3: Request Smuggling (High) - Upgraded to 1.15.5
  • tar: Arbitrary File Overwrite (High) - Upgraded to 7.5.6
  • devalue: DoS (High) - Upgraded to 5.6.2
  • diff: DoS (Low) - Upgraded to 5.2.2

Changes

  • Added pnpm.overrides to package.json forcing patched versions.
  • Updated pnpm-lock.yaml.

@justinvdm justinvdm merged commit 1d84c10 into main Jan 21, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant