Commit 0e58ac8
chore(security): resolve pnpm audit vulnerabilities (3 high, 3 moderate) (#438)
All 6 advisories are in transitive dependencies; none of the affected
packages is a direct dependency of any workspace package. Following the
existing convention, each is remediated by raising an existing
`pnpm.overrides` floor plus a lockfile refresh.
Override floors raised:
- brace-expansion >=5.0.8 -> >=5.0.9 (5.0.8 -> 5.0.9)
- fast-uri >=3.1.4 -> >=3.1.5 (3.1.4 -> 3.1.5)
- hono >=4.12.27 -> >=4.12.34 (4.12.32 -> 4.13.0)
- ip-address >=10.1.1 -> >=10.3.1 (10.2.0 -> 10.4.0)
fast-uri keeps its `<4` upper bound: 4.1.2 is the current `latest`, but
its consumer ajv 8.18.0 declares `fast-uri: ^3.0.1`, so a bare `>=3.1.5`
floor would resolve past ajv's supported range. The fix is backported to
the 3.x line, published as the `three` dist-tag.
The other three take a bare `>=` floor, consistent with the rest of the
overrides: no newer major exists for any of them, so no floor can jump a
major boundary. hono 4.13.0 satisfies both @modelcontextprotocol/sdk's
`^4.11.4` and @hono/node-server 2.0.12's `hono: ^4` peer range.
The three ip-address advisories (GHSA-mwp4-54f8-5fhr, GHSA-4xrf-jv44-h6hh,
GHSA-22jq-vg5j-6vgg) share one remediation; >=10.3.1 clears all three.
`pnpm audit` and `pnpm audit --prod` both report no known
vulnerabilities. Build, typecheck, license-check, lint and the full test
suite (2641 tests) pass.
Claude-Session: https://claude.ai/code/session_019ym25nnxoNoaVdX3CrZwUw
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>1 parent d339651 commit 0e58ac8
2 files changed
Lines changed: 28 additions & 28 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
66 | 66 | | |
67 | 67 | | |
68 | 68 | | |
69 | | - | |
| 69 | + | |
70 | 70 | | |
71 | 71 | | |
72 | 72 | | |
73 | | - | |
| 73 | + | |
74 | 74 | | |
75 | 75 | | |
76 | | - | |
77 | | - | |
| 76 | + | |
| 77 | + | |
78 | 78 | | |
79 | 79 | | |
80 | 80 | | |
| |||
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments