Repository navigation
fix(deps): clear the shell-quote and source-map-js audit advisories - #937
Conversation
`pnpm audit --audit-level=high` fails every catalog PR on two advisories against transitive dev dependencies: - shell-quote <1.11.0 (critical, GHSA-pqg4-j6r4-53mv), via @changesets/cli > launch-editor. launch-editor's range already admits the fix, so a re-resolve floats it to 1.12.0 with no override. - source-map-js <1.2.2 (high, GHSA-68fv-2mgg-jv7q), via vitest > vite > postcss. postcss's ^1.2.1 admits 1.2.2, but a targeted `pnpm update --depth Infinity` leaves the lock on 1.2.1, so it gets an override, documented beside the existing ones. Lockfile regenerated with pnpm. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013d2K3bFyT4kxepK9ViQt27
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. 7 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 8 reviews per hour. WalkthroughThe workspace override block now requires ChangesDependency security override
Priority: ⬆️ High Estimated code review effort: 1 (Trivial) | ~4 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The dependency fixes are reflected in the workspace configuration and lockfile; no actionable merge-blocking risk remains. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
main already carries the shell-quote and source-map-js overrides (#938), so both conflicts resolve to main's side. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UeZsHju3X3quco1MtZwaJD
Description
The
auditjob (pnpm audit --audit-level=high) fails on every open catalog PR. It flags two advisories published against transitive dev dependencies, so the job turns red without any change on the branch:shell-quote<1.11.0@changesets/cli > launch-editorpnpm update shell-quote --depth Infinityfloats it to 1.12.0source-map-js<1.2.2vitest > vite > postcsssource-map-js: ">=1.2.2". postcss's^1.2.1admits 1.2.2, but a targetedpnpm update source-map-js --depth Infinityleaves the lock on 1.2.1, so the floor is forcedshell-quoteis floated rather than pinned because the existing comment inpnpm-workspace.yamlasks for that: an override is only for a version that won't float. Both decisions are recorded in that comment block beside theviteandesbuildentries. The lockfile was regenerated withpnpm install --no-frozen-lockfileand was not hand-edited.pnpm install --frozen-lockfilethen runs clean against it.No Linear issue covers this exact change. It relates to AUREO-967 (giving override pins a review trigger): the new
source-map-jsfloor is one more pin of the kind that issue will audit.Type of Change
Checklist
pnpm validateand it passeshpI added or changed names its source in the description (n/a)Additional Notes
Run locally:
pnpm audit --audit-level=highreports no known vulnerabilities;pnpm linthas no errors;pnpm typecheck,pnpm test(730 pass),pnpm format:check,pnpm validate,pnpm validate:translationsandpnpm buildall pass. There is no changeset because the PR changes nodata/files, which the changeset workflow skips by design.Once this merges, every open catalog PR's
auditcheck goes green after mergingmaininto it.🤖 Generated with Claude Code
https://claude.ai/code/session_013d2K3bFyT4kxepK9ViQt27
Generated by Claude Code
Summary by CodeRabbit