Repository navigation
Override shell-quote and source-map-js for new audit advisories - #938
Conversation
pnpm audit --audit-level=high failed on every branch from two advisories in transitive dev dependencies: - shell-quote >=1.8.4 <1.11.0 via @changesets/cli > launch-editor (GHSA-pqg4-j6r4-53mv, critical) - source-map-js >=1.0.0 <1.2.2 via vitest > vite > postcss (GHSA-68fv-2mgg-jv7q, high) Add overrides for both to pnpm-workspace.yaml, document them beside the existing vite and esbuild notes, and regenerate the lockfile. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LN42VrsbfHPkKaYbLiq6qK
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. 7 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 8 reviews per hour. WalkthroughThe workspace file now documents security advisories and affected dependency chains for ChangesDependency security overrides
Priority: ⬆️ High Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The workspace and lockfile select patched versions for both affected dependencies; no concrete merge-blocking issue is indicated. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
main already carries the shell-quote and source-map-js overrides (#938), so both conflicts resolve to main's side. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UeZsHju3X3quco1MtZwaJD
Description
The
auditjob (pnpm audit --audit-level=high) fails on every branch because of two new advisories in transitive dev dependencies:shell-quote>=1.8.4 <1.11.0, via@changesets/cli > launch-editor > shell-quote(GHSA-pqg4-j6r4-53mv)source-map-js>=1.0.0 <1.2.2, viavitest > vite > postcss > source-map-js(GHSA-68fv-2mgg-jv7q)This PR only changes dependencies:
shell-quote: ">=1.11.0"andsource-map-js: ">=1.2.2"to theoverrides:block inpnpm-workspace.yaml, and documents both in the comment above it, in the same style as the vite and esbuild notes.pnpm-lock.yamlwithpnpm install --no-frozen-lockfile(18 lines). Only two packages move:shell-quote1.10.0 → 1.12.0 andsource-map-js1.2.1 → 1.2.2.There's no changeset because no
data/files changed, so the Changeset workflow's data check skips this PR.changeset status --since=HEADpasses.Once this merges, catalog#933 and catalog#935 can merge
mainin and go green.Type of Change
Checklist
pnpm validateand it passeshpI added or changed names its source in the description (n/a)Additional Notes
Checked locally:
pnpm audit --audit-level=highreports "No known vulnerabilities found" (before this change: 1 high, 1 critical)pnpm typecheckpassespnpm lintpasses, with only the warnings and infos that already existpnpm test: 36 files and 730 tests passpnpm install --frozen-lockfileis clean🤖 Generated with Claude Code
https://claude.ai/code/session_01LN42VrsbfHPkKaYbLiq6qK
Generated by Claude Code
Summary by CodeRabbit