Skip to content

Override shell-quote and source-map-js for new audit advisories - #938

Merged
jeffreylouden merged 1 commit into
mainfrom
claude/friendly-galileo-g6rbat
Oct 8, 2026
Merged

jeffreylouden merged 1 commit into
mainfrom
claude/friendly-galileo-g6rbat

Conversation

@jeffreylouden

@jeffreylouden jeffreylouden commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

Description

The audit job (pnpm audit --audit-level=high) fails on every branch because of two new advisories in transitive dev dependencies:

  • critical shell-quote >=1.8.4 <1.11.0, via @changesets/cli > launch-editor > shell-quote (GHSA-pqg4-j6r4-53mv)
  • high source-map-js >=1.0.0 <1.2.2, via vitest > vite > postcss > source-map-js (GHSA-68fv-2mgg-jv7q)

This PR only changes dependencies:

  • Adds shell-quote: ">=1.11.0" and source-map-js: ">=1.2.2" to the overrides: block in pnpm-workspace.yaml, and documents both in the comment above it, in the same style as the vite and esbuild notes.
  • Regenerates pnpm-lock.yaml with pnpm install --no-frozen-lockfile (18 lines). Only two packages move: shell-quote 1.10.0 → 1.12.0 and source-map-js 1.2.1 → 1.2.2.

There's no changeset because no data/ files changed, so the Changeset workflow's data check skips this PR. changeset status --since=HEAD passes.

Once this merges, catalog#933 and catalog#935 can merge main in and go green.

Type of Change

  • New software/plugin entry
  • New hardware entry
  • New manufacturer entry
  • Update to existing entry
  • Bug fix
  • Schema or script change

Checklist

  • I have run pnpm validate and it passes
  • YAML files follow the existing format
  • Manufacturer exists (or I'm adding it in this PR) (n/a)
  • Categories and formats are from the schema files (n/a)
  • Identifiers are accurate, if provided (n/a)
  • Any hp I added or changed names its source in the description (n/a)

Additional Notes

Checked locally:

  • pnpm audit --audit-level=high reports "No known vulnerabilities found" (before this change: 1 high, 1 critical)
  • pnpm typecheck passes
  • pnpm lint passes, with only the warnings and infos that already exist
  • pnpm test: 36 files and 730 tests pass
  • pnpm install --frozen-lockfile is clean

🤖 Generated with Claude Code

https://claude.ai/code/session_01LN42VrsbfHPkKaYbLiq6qK


Generated by Claude Code

Summary by CodeRabbit

  • Chores
    • Updated security safeguards to ensure fixes for known vulnerabilities are applied. This helps reduce exposure to reported security issues and keeps the application’s underlying components aligned with patched versions. No user-facing features or behavior changes are included in this update.

pnpm audit --audit-level=high failed on every branch from two advisories
in transitive dev dependencies:

- shell-quote >=1.8.4 <1.11.0 via @changesets/cli > launch-editor
  (GHSA-pqg4-j6r4-53mv, critical)
- source-map-js >=1.0.0 <1.2.2 via vitest > vite > postcss
  (GHSA-68fv-2mgg-jv7q, high)

Add overrides for both to pnpm-workspace.yaml, document them beside the
existing vite and esbuild notes, and regenerate the lockfile.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LN42VrsbfHPkKaYbLiq6qK
@changeset-bot

changeset-bot Bot commented Oct 8, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 319d8d3

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: existential-engineering/catalog/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: e7117f48-20f2-4d03-8844-b3d27f2609d8
📥 Commits

Reviewing files that changed from the base of the PR and between 6b2be7b and 319d8d3.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (1)
  • pnpm-workspace.yaml

Included review availability: This review used your included allowance. 7 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 8 reviews per hour.


Walkthrough

The workspace file now documents security advisories and affected dependency chains for shell-quote and source-map-js. It also sets minimum versions for both dependencies.

Changes

Dependency security overrides

Layer / File(s) Summary
Document advisories and set dependency overrides
pnpm-workspace.yaml
Comments identify dependency chains, advisories, and patched versions. Overrides require shell-quote 1.11.0 or later and source-map-js 1.2.2 or later.

Priority: ⬆️ High

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 319d8

The workspace and lockfile select patched versions for both affected dependencies; no concrete merge-blocking issue is indicated.

Architecture Summary

Architecture risk: 🔵 Low · up to 319d8

The change affects 1 system.

Changed systems: pnpm-workspace.yaml

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — pnpm-workspace.yaml (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in pnpm-workspace.yaml: Added comments identifying the affected dependency chains, vulnerability advisories, and patched versions for shell-quote and source-map-js.
  • observed — Modified behavior in pnpm-workspace.yaml: Added dependency overrides requiring shell-quote version 1.11.0 or later and source-map-js version 1.2.2 or later.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: adding dependency overrides for shell-quote and source-map-js to address audit advisories.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@jeffreylouden
jeffreylouden merged commit 820898f into main Oct 8, 2026
9 checks passed
@jeffreylouden
jeffreylouden deleted the claude/friendly-galileo-g6rbat branch October 8, 2026 11:37
jeffreylouden pushed a commit that referenced this pull request Oct 9, 2026
main already carries the shell-quote and source-map-js overrides
(#938), so both conflicts resolve to main's side.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UeZsHju3X3quco1MtZwaJD
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants