Skip to content

fix(deps): clear the shell-quote and source-map-js audit advisories - #937

Merged
jeffreylouden merged 2 commits into
mainfrom
fix/deps/audit-overrides
Oct 9, 2026
Merged

jeffreylouden merged 2 commits into
mainfrom
fix/deps/audit-overrides

Conversation

@jeffreylouden

@jeffreylouden jeffreylouden commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

Description

The audit job (pnpm audit --audit-level=high) fails on every open catalog PR. It flags two advisories published against transitive dev dependencies, so the job turns red without any change on the branch:

advisory package path fix
critical, GHSA-pqg4-j6r4-53mv shell-quote <1.11.0 @changesets/cli > launch-editor re-resolved, no override. launch-editor's range already admits the fix, and pnpm update shell-quote --depth Infinity floats it to 1.12.0
high, GHSA-68fv-2mgg-jv7q source-map-js <1.2.2 vitest > vite > postcss override source-map-js: ">=1.2.2". postcss's ^1.2.1 admits 1.2.2, but a targeted pnpm update source-map-js --depth Infinity leaves the lock on 1.2.1, so the floor is forced

shell-quote is floated rather than pinned because the existing comment in pnpm-workspace.yaml asks for that: an override is only for a version that won't float. Both decisions are recorded in that comment block beside the vite and esbuild entries. The lockfile was regenerated with pnpm install --no-frozen-lockfile and was not hand-edited. pnpm install --frozen-lockfile then runs clean against it.

No Linear issue covers this exact change. It relates to AUREO-967 (giving override pins a review trigger): the new source-map-js floor is one more pin of the kind that issue will audit.

Type of Change

  • Bug fix

Checklist

  • I have run pnpm validate and it passes
  • YAML files follow the existing format (no data changes)
  • Manufacturer exists (n/a)
  • Categories and formats are from the schema files (n/a)
  • Identifiers are accurate, if provided (n/a)
  • Any hp I added or changed names its source in the description (n/a)

Additional Notes

Run locally: pnpm audit --audit-level=high reports no known vulnerabilities; pnpm lint has no errors; pnpm typecheck, pnpm test (730 pass), pnpm format:check, pnpm validate, pnpm validate:translations and pnpm build all pass. There is no changeset because the PR changes no data/ files, which the changeset workflow skips by design.

Once this merges, every open catalog PR's audit check goes green after merging main into it.

🤖 Generated with Claude Code

https://claude.ai/code/session_013d2K3bFyT4kxepK9ViQt27


Generated by Claude Code

Summary by CodeRabbit

  • Bug Fixes
    • Strengthened security protections against an event-loop denial-of-service vulnerability. No changes to app functionality are expected.

`pnpm audit --audit-level=high` fails every catalog PR on two advisories
against transitive dev dependencies:

- shell-quote <1.11.0 (critical, GHSA-pqg4-j6r4-53mv), via
  @changesets/cli > launch-editor. launch-editor's range already admits
  the fix, so a re-resolve floats it to 1.12.0 with no override.
- source-map-js <1.2.2 (high, GHSA-68fv-2mgg-jv7q), via
  vitest > vite > postcss. postcss's ^1.2.1 admits 1.2.2, but a targeted
  `pnpm update --depth Infinity` leaves the lock on 1.2.1, so it gets an
  override, documented beside the existing ones.

Lockfile regenerated with pnpm.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013d2K3bFyT4kxepK9ViQt27
@changeset-bot

changeset-bot Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: cb2380e

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: existential-engineering/catalog/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 7e1c0f2d-4846-4f36-83f8-f9d8372965f8

📥 Commits

Reviewing files that changed from the base of the PR and between 6b2be7b and 07da80e.


⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml

📒 Files selected for processing (1)
  • pnpm-workspace.yaml

Included review availability: This review used your included allowance. 7 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 8 reviews per hour.



Walkthrough

The workspace override block now requires source-map-js version 1.2.2 or later. Comments describe the related advisory, the reason for the minimum version, and why no shell-quote override is needed.

Changes

Dependency security override

Layer / File(s) Summary
Document and enforce dependency floor
pnpm-workspace.yaml
Comments document the source-map-js advisory and explain why the minimum version is forced. They also state that shell-quote does not need an override. The override requires source-map-js version 1.2.2 or later.

Priority: ⬆️ High

Estimated code review effort: 1 (Trivial) | ~4 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 07da8

The dependency fixes are reflected in the workspace configuration and lockfile; no actionable merge-blocking risk remains.

Architecture Summary

Architecture risk: 🔵 Low · up to 07da8

The change affects 1 system.

Changed systems: pnpm-workspace.yaml

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — pnpm-workspace.yaml (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in pnpm-workspace.yaml: Added comments documenting the source-map-js vulnerability, why its minimum version must be forced, and why shell-quote does not require an override.
  • observed — Modified behavior in pnpm-workspace.yaml: Added a source-map-js override requiring version 1.2.2 or later.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely identifies the main change: resolving the shell-quote and source-map-js security advisories.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.


✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR


  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

main already carries the shell-quote and source-map-js overrides
(#938), so both conflicts resolve to main's side.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UeZsHju3X3quco1MtZwaJD
@jeffreylouden
jeffreylouden merged commit 7352fec into main Oct 9, 2026
7 checks passed
@jeffreylouden
jeffreylouden deleted the fix/deps/audit-overrides branch October 9, 2026 11:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants