chore(deps): clear 56 of the 62 open transitive advisories in the root lockfile - #56

Merged
radroid merged 2 commits into
mainfrom
t3x/dep-security-sweep
Aug 8, 2026
Merged

chore(deps): clear 56 of the 62 open transitive advisories in the root lockfile#56
radroid merged 2 commits into
mainfrom
t3x/dep-security-sweep

Conversation

@radroid

Copy link
Copy Markdown
Owner

Follow-up to #52. Dependabot opened no PRs for any of these — it generally cannot auto-fix transitive pnpm dependencies — so they had been accumulating untouched.

What moved

Two levers, deliberately in that order, because the cheaper one covers more than it looks.

1. Re-resolution, no config change at all. Several of these were already satisfiable by the ranges their parents declare; the lockfile was just holding a stale resolution. pnpm update -r --lockfile-only cleared astro (7.0.3 → 7.2.0), postcss (8.5.15 → 8.5.26), svgo (4.0.1 → 4.0.2), js-yaml (4.2.0 → 4.3.1) and undici@7 (7.27.1 → 7.29.0). pnpm update wanted to rewrite apps/marketing/package.json's specifier to ^7.2.0 as it went; I reverted that and re-resolved, and 7.2.0 holds under the original ^7.0.3. No package.json in the repo is touched by this PR.

2. Twelve major-scoped overrides: for the rest, appended to the block upstream already maintains in pnpm-workspace.yaml: brace-expansion (all three major lines), builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6. Every key is pinned to a major — "tar@7": ^7.5.21, not tar: ^7.5.21 — so no entry can silently cross a major in a package nothing here imports directly.

Net effect on the lockfile is a shrink of 413 lines: astro 7.2.0 sheds its old remark/rehype/hast pipeline.

What I deliberately did not fix

packageneedswhy not
image-size 1.2.1No patched version exists. Two high advisories, both <= 2.0.2 with no fix published. Nothing to bump to.
sharp 0.34.50.35.0Native binary with prebuilt gyp artifacts and an allowBuilds entry. In 0.x a minor bump is a breaking change; an override here risks the desktop build for one high advisory. Wants its own PR.
uuid 7.0.311.1.1Four majors. It arrives via a deprecated transitive path, so the real fix is dropping whatever still depends on uuid@7, not forcing 11 underneath it.

Two more alerts — @hono/node-server and @vitest/browser (critical) — name packages that are not in the lockfile at all. They look stale and should auto-close once GitHub rescans the default branch after this lands. Worth confirming rather than assuming.

That leaves 5 genuinely open, from 64.

Ledger

pnpm-workspace.yaml becomes row 37. pnpm-lock.yaml goes to risk 67136, five times the next row — and I added a note under the header saying not to read that number at face value: the lockfile is regenerated at every sync rather than merged, so the cost is one pnpm install, not a thousand conflict decisions. The 18-line overrides: block is what actually has to survive a sync, and it is the row to defend.

Verification is CI — typecheck, lint and the full suite. I did not install node_modules locally to run them; this machine is disk-constrained and the resolve was lockfile-only.

@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: f18ac851-bf89-4c45-958a-bf5e111f26ff

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@radroidradroid changed the title chore(deps): clear 57 of 64 transitive advisories in the root lockfilechore(deps): clear 56 of the 62 open transitive advisories in the root lockfileAug 8, 2026
@radroid

Copy link
Copy Markdown
OwnerAuthor

Correcting the counts in the description. I wrote them before #52 landed and they were off by one in two places. Measured against the live alert data rather than my earlier arithmetic:

  • 62 advisories open against the root pnpm-lock.yaml right now (the original 64 less the two electron ones chore(deps): bump electron from 41.5.0 to 41.10.3 in /apps/desktop #52 already closed).
  • 56 are cleared by this PR.
  • 6 remain: image-size ×2 (no patched version exists), sharp, uuid, and the two that name packages absent from the lockfile — @vitest/browser and @hono/node-server.

So the split is 4 knowingly deferred and 2 that look stale, not the "5 genuinely open" the description says. The title is updated; the reasoning in the table is unchanged.

@radroid
radroid merged commit 7fc46bb into mainAug 8, 2026
2 checks passed
@radroid
radroid deleted the t3x/dep-security-sweep branch August 8, 2026 06:25
@radroid

Copy link
Copy Markdown
OwnerAuthor

Correction to the description: the last two alerts are not stale. I wrote that @vitest/browser and @hono/node-server "name packages that are not in the lockfile at all." They are both in it. My check used grep -E '^ <pkg>@', and pnpm-lock.yamlsingle-quotes scoped package keys '@vitest/browser@4.1.9': — so the pattern silently matched nothing and I read that as absent. Unscoped packages were unaffected, so the rest of the triage stands.

What they actually are, and why each is still deferred rather than fixed:

@vitest/browser@4.1.9 → 4.1.10 (critical, dev-scoped).4.1.10 declares an exact peer, "vitest": "4.1.10", so it cannot move alone — it drags the whole family, and vitest here comes from vite-plus@0.2.2, which pins 4.1.9 across @vitest/{expect,mocker,runner,snapshot,spy,utils,pretty-format}. Bumping the test runner out from under the fork's only CI gate, to close an advisory in Vitest Browser Mode, which no vite.config.ts in this repo configures, is the wrong trade. It should ride along with the next vite-plus bump.

@hono/node-server@1.19.14 → 2.0.5 (medium, runtime). No 1.x fix exists; the patch is only in 2.0.5. It arrives via @modelcontextprotocol/sdk@1.29.0, which declares "@hono/node-server": "^1.19.9" — 1.x only. SDK 1.30.0 widens that to "^1.19.9 || ^2.0.5", and @anthropic-ai/claude-agent-sdk@0.3.170 already asks for ^1.29.0, so 1.30.0 is inside the range its own dependant wants. That looked like a clean two-line fix and it is not: the SDK is an auto-installed peer, not a regular dependency, so an overrides: entry rewrites the declared peer range (^1.29.0^1.30.0) and leaves the resolved instance at 1.29.0. pnpm update --depth Infinity does not move it either — nothing in this workspace declares the SDK, so there is nothing for update to act on. Landing it needs a full --force re-resolution of the lockfile, which is disproportionate for a Windows-only path traversal in serve-static. I tried it, reverted it, and left it.

So the real remaining count is 6, split 4 deferred with reasons (image-size ×2, sharp, uuid) and these 2 — not "4 deferred and 2 stale".

radroid added a commit that referenced this pull request Aug 8, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
github-actionsBot pushed a commit that referenced this pull request Aug 10, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 10, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 17, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 18, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@radroid
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore(deps): clear 56 of the 62 open transitive advisories in the root lockfile - #56

Merged
radroid merged 2 commits into
mainfrom
t3x/dep-security-sweep
Aug 8, 2026
Merged

chore(deps): clear 56 of the 62 open transitive advisories in the root lockfile#56
radroid merged 2 commits into
mainfrom
t3x/dep-security-sweep

Conversation

@radroid

Copy link
Copy Markdown
Owner

Follow-up to #52. Dependabot opened no PRs for any of these — it generally cannot auto-fix transitive pnpm dependencies — so they had been accumulating untouched.

What moved

Two levers, deliberately in that order, because the cheaper one covers more than it looks.

1. Re-resolution, no config change at all. Several of these were already satisfiable by the ranges their parents declare; the lockfile was just holding a stale resolution. pnpm update -r --lockfile-only cleared astro (7.0.3 → 7.2.0), postcss (8.5.15 → 8.5.26), svgo (4.0.1 → 4.0.2), js-yaml (4.2.0 → 4.3.1) and undici@7 (7.27.1 → 7.29.0). pnpm update wanted to rewrite apps/marketing/package.json's specifier to ^7.2.0 as it went; I reverted that and re-resolved, and 7.2.0 holds under the original ^7.0.3. No package.json in the repo is touched by this PR.

2. Twelve major-scoped overrides: for the rest, appended to the block upstream already maintains in pnpm-workspace.yaml: brace-expansion (all three major lines), builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6. Every key is pinned to a major — "tar@7": ^7.5.21, not tar: ^7.5.21 — so no entry can silently cross a major in a package nothing here imports directly.

Net effect on the lockfile is a shrink of 413 lines: astro 7.2.0 sheds its old remark/rehype/hast pipeline.

What I deliberately did not fix

packageneedswhy not
image-size 1.2.1No patched version exists. Two high advisories, both <= 2.0.2 with no fix published. Nothing to bump to.
sharp 0.34.50.35.0Native binary with prebuilt gyp artifacts and an allowBuilds entry. In 0.x a minor bump is a breaking change; an override here risks the desktop build for one high advisory. Wants its own PR.
uuid 7.0.311.1.1Four majors. It arrives via a deprecated transitive path, so the real fix is dropping whatever still depends on uuid@7, not forcing 11 underneath it.

Two more alerts — @hono/node-server and @vitest/browser (critical) — name packages that are not in the lockfile at all. They look stale and should auto-close once GitHub rescans the default branch after this lands. Worth confirming rather than assuming.

That leaves 5 genuinely open, from 64.

Ledger

pnpm-workspace.yaml becomes row 37. pnpm-lock.yaml goes to risk 67136, five times the next row — and I added a note under the header saying not to read that number at face value: the lockfile is regenerated at every sync rather than merged, so the cost is one pnpm install, not a thousand conflict decisions. The 18-line overrides: block is what actually has to survive a sync, and it is the row to defend.

Verification is CI — typecheck, lint and the full suite. I did not install node_modules locally to run them; this machine is disk-constrained and the resolve was lockfile-only.

@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: f18ac851-bf89-4c45-958a-bf5e111f26ff

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@radroidradroid changed the title chore(deps): clear 57 of 64 transitive advisories in the root lockfilechore(deps): clear 56 of the 62 open transitive advisories in the root lockfileAug 8, 2026
@radroid

Copy link
Copy Markdown
OwnerAuthor

Correcting the counts in the description. I wrote them before #52 landed and they were off by one in two places. Measured against the live alert data rather than my earlier arithmetic:

  • 62 advisories open against the root pnpm-lock.yaml right now (the original 64 less the two electron ones chore(deps): bump electron from 41.5.0 to 41.10.3 in /apps/desktop #52 already closed).
  • 56 are cleared by this PR.
  • 6 remain: image-size ×2 (no patched version exists), sharp, uuid, and the two that name packages absent from the lockfile — @vitest/browser and @hono/node-server.

So the split is 4 knowingly deferred and 2 that look stale, not the "5 genuinely open" the description says. The title is updated; the reasoning in the table is unchanged.

@radroid
radroid merged commit 7fc46bb into mainAug 8, 2026
2 checks passed
@radroid
radroid deleted the t3x/dep-security-sweep branch August 8, 2026 06:25
@radroid

Copy link
Copy Markdown
OwnerAuthor

Correction to the description: the last two alerts are not stale. I wrote that @vitest/browser and @hono/node-server "name packages that are not in the lockfile at all." They are both in it. My check used grep -E '^ <pkg>@', and pnpm-lock.yamlsingle-quotes scoped package keys '@vitest/browser@4.1.9': — so the pattern silently matched nothing and I read that as absent. Unscoped packages were unaffected, so the rest of the triage stands.

What they actually are, and why each is still deferred rather than fixed:

@vitest/browser@4.1.9 → 4.1.10 (critical, dev-scoped).4.1.10 declares an exact peer, "vitest": "4.1.10", so it cannot move alone — it drags the whole family, and vitest here comes from vite-plus@0.2.2, which pins 4.1.9 across @vitest/{expect,mocker,runner,snapshot,spy,utils,pretty-format}. Bumping the test runner out from under the fork's only CI gate, to close an advisory in Vitest Browser Mode, which no vite.config.ts in this repo configures, is the wrong trade. It should ride along with the next vite-plus bump.

@hono/node-server@1.19.14 → 2.0.5 (medium, runtime). No 1.x fix exists; the patch is only in 2.0.5. It arrives via @modelcontextprotocol/sdk@1.29.0, which declares "@hono/node-server": "^1.19.9" — 1.x only. SDK 1.30.0 widens that to "^1.19.9 || ^2.0.5", and @anthropic-ai/claude-agent-sdk@0.3.170 already asks for ^1.29.0, so 1.30.0 is inside the range its own dependant wants. That looked like a clean two-line fix and it is not: the SDK is an auto-installed peer, not a regular dependency, so an overrides: entry rewrites the declared peer range (^1.29.0^1.30.0) and leaves the resolved instance at 1.29.0. pnpm update --depth Infinity does not move it either — nothing in this workspace declares the SDK, so there is nothing for update to act on. Landing it needs a full --force re-resolution of the lockfile, which is disproportionate for a Windows-only path traversal in serve-static. I tried it, reverted it, and left it.

So the real remaining count is 6, split 4 deferred with reasons (image-size ×2, sharp, uuid) and these 2 — not "4 deferred and 2 stale".

radroid added a commit that referenced this pull request Aug 8, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
github-actionsBot pushed a commit that referenced this pull request Aug 10, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 10, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 17, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 18, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@radroid
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): clear 56 of the 62 open transitive advisories in the root lockfile - #56

Merged
radroid merged 2 commits into
mainfrom
t3x/dep-security-sweep
Aug 8, 2026
Merged

chore(deps): clear 56 of the 62 open transitive advisories in the root lockfile#56
radroid merged 2 commits into
mainfrom
t3x/dep-security-sweep

Conversation

@radroid

Copy link
Copy Markdown
Owner

Follow-up to #52. Dependabot opened no PRs for any of these — it generally cannot auto-fix transitive pnpm dependencies — so they had been accumulating untouched.

What moved

Two levers, deliberately in that order, because the cheaper one covers more than it looks.

1. Re-resolution, no config change at all. Several of these were already satisfiable by the ranges their parents declare; the lockfile was just holding a stale resolution. pnpm update -r --lockfile-only cleared astro (7.0.3 → 7.2.0), postcss (8.5.15 → 8.5.26), svgo (4.0.1 → 4.0.2), js-yaml (4.2.0 → 4.3.1) and undici@7 (7.27.1 → 7.29.0). pnpm update wanted to rewrite apps/marketing/package.json's specifier to ^7.2.0 as it went; I reverted that and re-resolved, and 7.2.0 holds under the original ^7.0.3. No package.json in the repo is touched by this PR.

2. Twelve major-scoped overrides: for the rest, appended to the block upstream already maintains in pnpm-workspace.yaml: brace-expansion (all three major lines), builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6. Every key is pinned to a major — "tar@7": ^7.5.21, not tar: ^7.5.21 — so no entry can silently cross a major in a package nothing here imports directly.

Net effect on the lockfile is a shrink of 413 lines: astro 7.2.0 sheds its old remark/rehype/hast pipeline.

What I deliberately did not fix

packageneedswhy not
image-size 1.2.1No patched version exists. Two high advisories, both <= 2.0.2 with no fix published. Nothing to bump to.
sharp 0.34.50.35.0Native binary with prebuilt gyp artifacts and an allowBuilds entry. In 0.x a minor bump is a breaking change; an override here risks the desktop build for one high advisory. Wants its own PR.
uuid 7.0.311.1.1Four majors. It arrives via a deprecated transitive path, so the real fix is dropping whatever still depends on uuid@7, not forcing 11 underneath it.

Two more alerts — @hono/node-server and @vitest/browser (critical) — name packages that are not in the lockfile at all. They look stale and should auto-close once GitHub rescans the default branch after this lands. Worth confirming rather than assuming.

That leaves 5 genuinely open, from 64.

Ledger

pnpm-workspace.yaml becomes row 37. pnpm-lock.yaml goes to risk 67136, five times the next row — and I added a note under the header saying not to read that number at face value: the lockfile is regenerated at every sync rather than merged, so the cost is one pnpm install, not a thousand conflict decisions. The 18-line overrides: block is what actually has to survive a sync, and it is the row to defend.

Verification is CI — typecheck, lint and the full suite. I did not install node_modules locally to run them; this machine is disk-constrained and the resolve was lockfile-only.

@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: f18ac851-bf89-4c45-958a-bf5e111f26ff

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@radroidradroid changed the title chore(deps): clear 57 of 64 transitive advisories in the root lockfilechore(deps): clear 56 of the 62 open transitive advisories in the root lockfileAug 8, 2026
@radroid

Copy link
Copy Markdown
OwnerAuthor

Correcting the counts in the description. I wrote them before #52 landed and they were off by one in two places. Measured against the live alert data rather than my earlier arithmetic:

  • 62 advisories open against the root pnpm-lock.yaml right now (the original 64 less the two electron ones chore(deps): bump electron from 41.5.0 to 41.10.3 in /apps/desktop #52 already closed).
  • 56 are cleared by this PR.
  • 6 remain: image-size ×2 (no patched version exists), sharp, uuid, and the two that name packages absent from the lockfile — @vitest/browser and @hono/node-server.

So the split is 4 knowingly deferred and 2 that look stale, not the "5 genuinely open" the description says. The title is updated; the reasoning in the table is unchanged.

@radroid
radroid merged commit 7fc46bb into mainAug 8, 2026
2 checks passed
@radroid
radroid deleted the t3x/dep-security-sweep branch August 8, 2026 06:25
@radroid

Copy link
Copy Markdown
OwnerAuthor

Correction to the description: the last two alerts are not stale. I wrote that @vitest/browser and @hono/node-server "name packages that are not in the lockfile at all." They are both in it. My check used grep -E '^ <pkg>@', and pnpm-lock.yamlsingle-quotes scoped package keys '@vitest/browser@4.1.9': — so the pattern silently matched nothing and I read that as absent. Unscoped packages were unaffected, so the rest of the triage stands.

What they actually are, and why each is still deferred rather than fixed:

@vitest/browser@4.1.9 → 4.1.10 (critical, dev-scoped).4.1.10 declares an exact peer, "vitest": "4.1.10", so it cannot move alone — it drags the whole family, and vitest here comes from vite-plus@0.2.2, which pins 4.1.9 across @vitest/{expect,mocker,runner,snapshot,spy,utils,pretty-format}. Bumping the test runner out from under the fork's only CI gate, to close an advisory in Vitest Browser Mode, which no vite.config.ts in this repo configures, is the wrong trade. It should ride along with the next vite-plus bump.

@hono/node-server@1.19.14 → 2.0.5 (medium, runtime). No 1.x fix exists; the patch is only in 2.0.5. It arrives via @modelcontextprotocol/sdk@1.29.0, which declares "@hono/node-server": "^1.19.9" — 1.x only. SDK 1.30.0 widens that to "^1.19.9 || ^2.0.5", and @anthropic-ai/claude-agent-sdk@0.3.170 already asks for ^1.29.0, so 1.30.0 is inside the range its own dependant wants. That looked like a clean two-line fix and it is not: the SDK is an auto-installed peer, not a regular dependency, so an overrides: entry rewrites the declared peer range (^1.29.0^1.30.0) and leaves the resolved instance at 1.29.0. pnpm update --depth Infinity does not move it either — nothing in this workspace declares the SDK, so there is nothing for update to act on. Landing it needs a full --force re-resolution of the lockfile, which is disproportionate for a Windows-only path traversal in serve-static. I tried it, reverted it, and left it.

So the real remaining count is 6, split 4 deferred with reasons (image-size ×2, sharp, uuid) and these 2 — not "4 deferred and 2 stale".

radroid added a commit that referenced this pull request Aug 8, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
github-actionsBot pushed a commit that referenced this pull request Aug 10, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 10, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 17, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 18, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@radroid
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): clear 56 of the 62 open transitive advisories in the root lockfile - #56

Merged
radroid merged 2 commits into
mainfrom
t3x/dep-security-sweep
Aug 8, 2026
Merged

chore(deps): clear 56 of the 62 open transitive advisories in the root lockfile#56
radroid merged 2 commits into
mainfrom
t3x/dep-security-sweep

Conversation

@radroid

Copy link
Copy Markdown
Owner

Follow-up to #52. Dependabot opened no PRs for any of these — it generally cannot auto-fix transitive pnpm dependencies — so they had been accumulating untouched.

What moved

Two levers, deliberately in that order, because the cheaper one covers more than it looks.

1. Re-resolution, no config change at all. Several of these were already satisfiable by the ranges their parents declare; the lockfile was just holding a stale resolution. pnpm update -r --lockfile-only cleared astro (7.0.3 → 7.2.0), postcss (8.5.15 → 8.5.26), svgo (4.0.1 → 4.0.2), js-yaml (4.2.0 → 4.3.1) and undici@7 (7.27.1 → 7.29.0). pnpm update wanted to rewrite apps/marketing/package.json's specifier to ^7.2.0 as it went; I reverted that and re-resolved, and 7.2.0 holds under the original ^7.0.3. No package.json in the repo is touched by this PR.

2. Twelve major-scoped overrides: for the rest, appended to the block upstream already maintains in pnpm-workspace.yaml: brace-expansion (all three major lines), builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6. Every key is pinned to a major — "tar@7": ^7.5.21, not tar: ^7.5.21 — so no entry can silently cross a major in a package nothing here imports directly.

Net effect on the lockfile is a shrink of 413 lines: astro 7.2.0 sheds its old remark/rehype/hast pipeline.

What I deliberately did not fix

packageneedswhy not
image-size 1.2.1No patched version exists. Two high advisories, both <= 2.0.2 with no fix published. Nothing to bump to.
sharp 0.34.50.35.0Native binary with prebuilt gyp artifacts and an allowBuilds entry. In 0.x a minor bump is a breaking change; an override here risks the desktop build for one high advisory. Wants its own PR.
uuid 7.0.311.1.1Four majors. It arrives via a deprecated transitive path, so the real fix is dropping whatever still depends on uuid@7, not forcing 11 underneath it.

Two more alerts — @hono/node-server and @vitest/browser (critical) — name packages that are not in the lockfile at all. They look stale and should auto-close once GitHub rescans the default branch after this lands. Worth confirming rather than assuming.

That leaves 5 genuinely open, from 64.

Ledger

pnpm-workspace.yaml becomes row 37. pnpm-lock.yaml goes to risk 67136, five times the next row — and I added a note under the header saying not to read that number at face value: the lockfile is regenerated at every sync rather than merged, so the cost is one pnpm install, not a thousand conflict decisions. The 18-line overrides: block is what actually has to survive a sync, and it is the row to defend.

Verification is CI — typecheck, lint and the full suite. I did not install node_modules locally to run them; this machine is disk-constrained and the resolve was lockfile-only.

@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: f18ac851-bf89-4c45-958a-bf5e111f26ff

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@radroidradroid changed the title chore(deps): clear 57 of 64 transitive advisories in the root lockfilechore(deps): clear 56 of the 62 open transitive advisories in the root lockfileAug 8, 2026
@radroid

Copy link
Copy Markdown
OwnerAuthor

Correcting the counts in the description. I wrote them before #52 landed and they were off by one in two places. Measured against the live alert data rather than my earlier arithmetic:

  • 62 advisories open against the root pnpm-lock.yaml right now (the original 64 less the two electron ones chore(deps): bump electron from 41.5.0 to 41.10.3 in /apps/desktop #52 already closed).
  • 56 are cleared by this PR.
  • 6 remain: image-size ×2 (no patched version exists), sharp, uuid, and the two that name packages absent from the lockfile — @vitest/browser and @hono/node-server.

So the split is 4 knowingly deferred and 2 that look stale, not the "5 genuinely open" the description says. The title is updated; the reasoning in the table is unchanged.

@radroid
radroid merged commit 7fc46bb into mainAug 8, 2026
2 checks passed
@radroid
radroid deleted the t3x/dep-security-sweep branch August 8, 2026 06:25
@radroid

Copy link
Copy Markdown
OwnerAuthor

Correction to the description: the last two alerts are not stale. I wrote that @vitest/browser and @hono/node-server "name packages that are not in the lockfile at all." They are both in it. My check used grep -E '^ <pkg>@', and pnpm-lock.yamlsingle-quotes scoped package keys '@vitest/browser@4.1.9': — so the pattern silently matched nothing and I read that as absent. Unscoped packages were unaffected, so the rest of the triage stands.

What they actually are, and why each is still deferred rather than fixed:

@vitest/browser@4.1.9 → 4.1.10 (critical, dev-scoped).4.1.10 declares an exact peer, "vitest": "4.1.10", so it cannot move alone — it drags the whole family, and vitest here comes from vite-plus@0.2.2, which pins 4.1.9 across @vitest/{expect,mocker,runner,snapshot,spy,utils,pretty-format}. Bumping the test runner out from under the fork's only CI gate, to close an advisory in Vitest Browser Mode, which no vite.config.ts in this repo configures, is the wrong trade. It should ride along with the next vite-plus bump.

@hono/node-server@1.19.14 → 2.0.5 (medium, runtime). No 1.x fix exists; the patch is only in 2.0.5. It arrives via @modelcontextprotocol/sdk@1.29.0, which declares "@hono/node-server": "^1.19.9" — 1.x only. SDK 1.30.0 widens that to "^1.19.9 || ^2.0.5", and @anthropic-ai/claude-agent-sdk@0.3.170 already asks for ^1.29.0, so 1.30.0 is inside the range its own dependant wants. That looked like a clean two-line fix and it is not: the SDK is an auto-installed peer, not a regular dependency, so an overrides: entry rewrites the declared peer range (^1.29.0^1.30.0) and leaves the resolved instance at 1.29.0. pnpm update --depth Infinity does not move it either — nothing in this workspace declares the SDK, so there is nothing for update to act on. Landing it needs a full --force re-resolution of the lockfile, which is disproportionate for a Windows-only path traversal in serve-static. I tried it, reverted it, and left it.

So the real remaining count is 6, split 4 deferred with reasons (image-size ×2, sharp, uuid) and these 2 — not "4 deferred and 2 stale".

radroid added a commit that referenced this pull request Aug 8, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
github-actionsBot pushed a commit that referenced this pull request Aug 10, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 10, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 17, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 18, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@radroid
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore(deps): clear 56 of the 62 open transitive advisories in the root lockfile - #56

Merged
radroid merged 2 commits into
mainfrom
t3x/dep-security-sweep
Aug 8, 2026
Merged

chore(deps): clear 56 of the 62 open transitive advisories in the root lockfile#56
radroid merged 2 commits into
mainfrom
t3x/dep-security-sweep

Conversation

@radroid

Copy link
Copy Markdown
Owner

Follow-up to #52. Dependabot opened no PRs for any of these — it generally cannot auto-fix transitive pnpm dependencies — so they had been accumulating untouched.

What moved

Two levers, deliberately in that order, because the cheaper one covers more than it looks.

1. Re-resolution, no config change at all. Several of these were already satisfiable by the ranges their parents declare; the lockfile was just holding a stale resolution. pnpm update -r --lockfile-only cleared astro (7.0.3 → 7.2.0), postcss (8.5.15 → 8.5.26), svgo (4.0.1 → 4.0.2), js-yaml (4.2.0 → 4.3.1) and undici@7 (7.27.1 → 7.29.0). pnpm update wanted to rewrite apps/marketing/package.json's specifier to ^7.2.0 as it went; I reverted that and re-resolved, and 7.2.0 holds under the original ^7.0.3. No package.json in the repo is touched by this PR.

2. Twelve major-scoped overrides: for the rest, appended to the block upstream already maintains in pnpm-workspace.yaml: brace-expansion (all three major lines), builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6. Every key is pinned to a major — "tar@7": ^7.5.21, not tar: ^7.5.21 — so no entry can silently cross a major in a package nothing here imports directly.

Net effect on the lockfile is a shrink of 413 lines: astro 7.2.0 sheds its old remark/rehype/hast pipeline.

What I deliberately did not fix

packageneedswhy not
image-size 1.2.1No patched version exists. Two high advisories, both <= 2.0.2 with no fix published. Nothing to bump to.
sharp 0.34.50.35.0Native binary with prebuilt gyp artifacts and an allowBuilds entry. In 0.x a minor bump is a breaking change; an override here risks the desktop build for one high advisory. Wants its own PR.
uuid 7.0.311.1.1Four majors. It arrives via a deprecated transitive path, so the real fix is dropping whatever still depends on uuid@7, not forcing 11 underneath it.

Two more alerts — @hono/node-server and @vitest/browser (critical) — name packages that are not in the lockfile at all. They look stale and should auto-close once GitHub rescans the default branch after this lands. Worth confirming rather than assuming.

That leaves 5 genuinely open, from 64.

Ledger

pnpm-workspace.yaml becomes row 37. pnpm-lock.yaml goes to risk 67136, five times the next row — and I added a note under the header saying not to read that number at face value: the lockfile is regenerated at every sync rather than merged, so the cost is one pnpm install, not a thousand conflict decisions. The 18-line overrides: block is what actually has to survive a sync, and it is the row to defend.

Verification is CI — typecheck, lint and the full suite. I did not install node_modules locally to run them; this machine is disk-constrained and the resolve was lockfile-only.

@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: f18ac851-bf89-4c45-958a-bf5e111f26ff

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@radroidradroid changed the title chore(deps): clear 57 of 64 transitive advisories in the root lockfilechore(deps): clear 56 of the 62 open transitive advisories in the root lockfileAug 8, 2026
@radroid

Copy link
Copy Markdown
OwnerAuthor

Correcting the counts in the description. I wrote them before #52 landed and they were off by one in two places. Measured against the live alert data rather than my earlier arithmetic:

  • 62 advisories open against the root pnpm-lock.yaml right now (the original 64 less the two electron ones chore(deps): bump electron from 41.5.0 to 41.10.3 in /apps/desktop #52 already closed).
  • 56 are cleared by this PR.
  • 6 remain: image-size ×2 (no patched version exists), sharp, uuid, and the two that name packages absent from the lockfile — @vitest/browser and @hono/node-server.

So the split is 4 knowingly deferred and 2 that look stale, not the "5 genuinely open" the description says. The title is updated; the reasoning in the table is unchanged.

@radroid
radroid merged commit 7fc46bb into mainAug 8, 2026
2 checks passed
@radroid
radroid deleted the t3x/dep-security-sweep branch August 8, 2026 06:25
@radroid

Copy link
Copy Markdown
OwnerAuthor

Correction to the description: the last two alerts are not stale. I wrote that @vitest/browser and @hono/node-server "name packages that are not in the lockfile at all." They are both in it. My check used grep -E '^ <pkg>@', and pnpm-lock.yamlsingle-quotes scoped package keys '@vitest/browser@4.1.9': — so the pattern silently matched nothing and I read that as absent. Unscoped packages were unaffected, so the rest of the triage stands.

What they actually are, and why each is still deferred rather than fixed:

@vitest/browser@4.1.9 → 4.1.10 (critical, dev-scoped).4.1.10 declares an exact peer, "vitest": "4.1.10", so it cannot move alone — it drags the whole family, and vitest here comes from vite-plus@0.2.2, which pins 4.1.9 across @vitest/{expect,mocker,runner,snapshot,spy,utils,pretty-format}. Bumping the test runner out from under the fork's only CI gate, to close an advisory in Vitest Browser Mode, which no vite.config.ts in this repo configures, is the wrong trade. It should ride along with the next vite-plus bump.

@hono/node-server@1.19.14 → 2.0.5 (medium, runtime). No 1.x fix exists; the patch is only in 2.0.5. It arrives via @modelcontextprotocol/sdk@1.29.0, which declares "@hono/node-server": "^1.19.9" — 1.x only. SDK 1.30.0 widens that to "^1.19.9 || ^2.0.5", and @anthropic-ai/claude-agent-sdk@0.3.170 already asks for ^1.29.0, so 1.30.0 is inside the range its own dependant wants. That looked like a clean two-line fix and it is not: the SDK is an auto-installed peer, not a regular dependency, so an overrides: entry rewrites the declared peer range (^1.29.0^1.30.0) and leaves the resolved instance at 1.29.0. pnpm update --depth Infinity does not move it either — nothing in this workspace declares the SDK, so there is nothing for update to act on. Landing it needs a full --force re-resolution of the lockfile, which is disproportionate for a Windows-only path traversal in serve-static. I tried it, reverted it, and left it.

So the real remaining count is 6, split 4 deferred with reasons (image-size ×2, sharp, uuid) and these 2 — not "4 deferred and 2 stale".

radroid added a commit that referenced this pull request Aug 8, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
github-actionsBot pushed a commit that referenced this pull request Aug 10, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 10, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 17, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 18, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@radroid
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): clear 56 of the 62 open transitive advisories in the root lockfile - #56

Merged
radroid merged 2 commits into
mainfrom
t3x/dep-security-sweep
Aug 8, 2026
Merged

chore(deps): clear 56 of the 62 open transitive advisories in the root lockfile#56
radroid merged 2 commits into
mainfrom
t3x/dep-security-sweep

Conversation

@radroid

Copy link
Copy Markdown
Owner

Follow-up to #52. Dependabot opened no PRs for any of these — it generally cannot auto-fix transitive pnpm dependencies — so they had been accumulating untouched.

What moved

Two levers, deliberately in that order, because the cheaper one covers more than it looks.

1. Re-resolution, no config change at all. Several of these were already satisfiable by the ranges their parents declare; the lockfile was just holding a stale resolution. pnpm update -r --lockfile-only cleared astro (7.0.3 → 7.2.0), postcss (8.5.15 → 8.5.26), svgo (4.0.1 → 4.0.2), js-yaml (4.2.0 → 4.3.1) and undici@7 (7.27.1 → 7.29.0). pnpm update wanted to rewrite apps/marketing/package.json's specifier to ^7.2.0 as it went; I reverted that and re-resolved, and 7.2.0 holds under the original ^7.0.3. No package.json in the repo is touched by this PR.

2. Twelve major-scoped overrides: for the rest, appended to the block upstream already maintains in pnpm-workspace.yaml: brace-expansion (all three major lines), builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6. Every key is pinned to a major — "tar@7": ^7.5.21, not tar: ^7.5.21 — so no entry can silently cross a major in a package nothing here imports directly.

Net effect on the lockfile is a shrink of 413 lines: astro 7.2.0 sheds its old remark/rehype/hast pipeline.

What I deliberately did not fix

packageneedswhy not
image-size 1.2.1No patched version exists. Two high advisories, both <= 2.0.2 with no fix published. Nothing to bump to.
sharp 0.34.50.35.0Native binary with prebuilt gyp artifacts and an allowBuilds entry. In 0.x a minor bump is a breaking change; an override here risks the desktop build for one high advisory. Wants its own PR.
uuid 7.0.311.1.1Four majors. It arrives via a deprecated transitive path, so the real fix is dropping whatever still depends on uuid@7, not forcing 11 underneath it.

Two more alerts — @hono/node-server and @vitest/browser (critical) — name packages that are not in the lockfile at all. They look stale and should auto-close once GitHub rescans the default branch after this lands. Worth confirming rather than assuming.

That leaves 5 genuinely open, from 64.

Ledger

pnpm-workspace.yaml becomes row 37. pnpm-lock.yaml goes to risk 67136, five times the next row — and I added a note under the header saying not to read that number at face value: the lockfile is regenerated at every sync rather than merged, so the cost is one pnpm install, not a thousand conflict decisions. The 18-line overrides: block is what actually has to survive a sync, and it is the row to defend.

Verification is CI — typecheck, lint and the full suite. I did not install node_modules locally to run them; this machine is disk-constrained and the resolve was lockfile-only.

@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: f18ac851-bf89-4c45-958a-bf5e111f26ff

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@radroidradroid changed the title chore(deps): clear 57 of 64 transitive advisories in the root lockfilechore(deps): clear 56 of the 62 open transitive advisories in the root lockfileAug 8, 2026
@radroid

Copy link
Copy Markdown
OwnerAuthor

Correcting the counts in the description. I wrote them before #52 landed and they were off by one in two places. Measured against the live alert data rather than my earlier arithmetic:

  • 62 advisories open against the root pnpm-lock.yaml right now (the original 64 less the two electron ones chore(deps): bump electron from 41.5.0 to 41.10.3 in /apps/desktop #52 already closed).
  • 56 are cleared by this PR.
  • 6 remain: image-size ×2 (no patched version exists), sharp, uuid, and the two that name packages absent from the lockfile — @vitest/browser and @hono/node-server.

So the split is 4 knowingly deferred and 2 that look stale, not the "5 genuinely open" the description says. The title is updated; the reasoning in the table is unchanged.

@radroid
radroid merged commit 7fc46bb into mainAug 8, 2026
2 checks passed
@radroid
radroid deleted the t3x/dep-security-sweep branch August 8, 2026 06:25
@radroid

Copy link
Copy Markdown
OwnerAuthor

Correction to the description: the last two alerts are not stale. I wrote that @vitest/browser and @hono/node-server "name packages that are not in the lockfile at all." They are both in it. My check used grep -E '^ <pkg>@', and pnpm-lock.yamlsingle-quotes scoped package keys '@vitest/browser@4.1.9': — so the pattern silently matched nothing and I read that as absent. Unscoped packages were unaffected, so the rest of the triage stands.

What they actually are, and why each is still deferred rather than fixed:

@vitest/browser@4.1.9 → 4.1.10 (critical, dev-scoped).4.1.10 declares an exact peer, "vitest": "4.1.10", so it cannot move alone — it drags the whole family, and vitest here comes from vite-plus@0.2.2, which pins 4.1.9 across @vitest/{expect,mocker,runner,snapshot,spy,utils,pretty-format}. Bumping the test runner out from under the fork's only CI gate, to close an advisory in Vitest Browser Mode, which no vite.config.ts in this repo configures, is the wrong trade. It should ride along with the next vite-plus bump.

@hono/node-server@1.19.14 → 2.0.5 (medium, runtime). No 1.x fix exists; the patch is only in 2.0.5. It arrives via @modelcontextprotocol/sdk@1.29.0, which declares "@hono/node-server": "^1.19.9" — 1.x only. SDK 1.30.0 widens that to "^1.19.9 || ^2.0.5", and @anthropic-ai/claude-agent-sdk@0.3.170 already asks for ^1.29.0, so 1.30.0 is inside the range its own dependant wants. That looked like a clean two-line fix and it is not: the SDK is an auto-installed peer, not a regular dependency, so an overrides: entry rewrites the declared peer range (^1.29.0^1.30.0) and leaves the resolved instance at 1.29.0. pnpm update --depth Infinity does not move it either — nothing in this workspace declares the SDK, so there is nothing for update to act on. Landing it needs a full --force re-resolution of the lockfile, which is disproportionate for a Windows-only path traversal in serve-static. I tried it, reverted it, and left it.

So the real remaining count is 6, split 4 deferred with reasons (image-size ×2, sharp, uuid) and these 2 — not "4 deferred and 2 stale".

radroid added a commit that referenced this pull request Aug 8, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
github-actionsBot pushed a commit that referenced this pull request Aug 10, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 10, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 17, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 18, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@radroid
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): clear 56 of the 62 open transitive advisories in the root lockfile - #56

Merged
radroid merged 2 commits into
mainfrom
t3x/dep-security-sweep
Aug 8, 2026
Merged

chore(deps): clear 56 of the 62 open transitive advisories in the root lockfile#56
radroid merged 2 commits into
mainfrom
t3x/dep-security-sweep

Conversation

@radroid

Copy link
Copy Markdown
Owner

Follow-up to #52. Dependabot opened no PRs for any of these — it generally cannot auto-fix transitive pnpm dependencies — so they had been accumulating untouched.

What moved

Two levers, deliberately in that order, because the cheaper one covers more than it looks.

1. Re-resolution, no config change at all. Several of these were already satisfiable by the ranges their parents declare; the lockfile was just holding a stale resolution. pnpm update -r --lockfile-only cleared astro (7.0.3 → 7.2.0), postcss (8.5.15 → 8.5.26), svgo (4.0.1 → 4.0.2), js-yaml (4.2.0 → 4.3.1) and undici@7 (7.27.1 → 7.29.0). pnpm update wanted to rewrite apps/marketing/package.json's specifier to ^7.2.0 as it went; I reverted that and re-resolved, and 7.2.0 holds under the original ^7.0.3. No package.json in the repo is touched by this PR.

2. Twelve major-scoped overrides: for the rest, appended to the block upstream already maintains in pnpm-workspace.yaml: brace-expansion (all three major lines), builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6. Every key is pinned to a major — "tar@7": ^7.5.21, not tar: ^7.5.21 — so no entry can silently cross a major in a package nothing here imports directly.

Net effect on the lockfile is a shrink of 413 lines: astro 7.2.0 sheds its old remark/rehype/hast pipeline.

What I deliberately did not fix

packageneedswhy not
image-size 1.2.1No patched version exists. Two high advisories, both <= 2.0.2 with no fix published. Nothing to bump to.
sharp 0.34.50.35.0Native binary with prebuilt gyp artifacts and an allowBuilds entry. In 0.x a minor bump is a breaking change; an override here risks the desktop build for one high advisory. Wants its own PR.
uuid 7.0.311.1.1Four majors. It arrives via a deprecated transitive path, so the real fix is dropping whatever still depends on uuid@7, not forcing 11 underneath it.

Two more alerts — @hono/node-server and @vitest/browser (critical) — name packages that are not in the lockfile at all. They look stale and should auto-close once GitHub rescans the default branch after this lands. Worth confirming rather than assuming.

That leaves 5 genuinely open, from 64.

Ledger

pnpm-workspace.yaml becomes row 37. pnpm-lock.yaml goes to risk 67136, five times the next row — and I added a note under the header saying not to read that number at face value: the lockfile is regenerated at every sync rather than merged, so the cost is one pnpm install, not a thousand conflict decisions. The 18-line overrides: block is what actually has to survive a sync, and it is the row to defend.

Verification is CI — typecheck, lint and the full suite. I did not install node_modules locally to run them; this machine is disk-constrained and the resolve was lockfile-only.

@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: f18ac851-bf89-4c45-958a-bf5e111f26ff

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@radroidradroid changed the title chore(deps): clear 57 of 64 transitive advisories in the root lockfilechore(deps): clear 56 of the 62 open transitive advisories in the root lockfileAug 8, 2026
@radroid

Copy link
Copy Markdown
OwnerAuthor

Correcting the counts in the description. I wrote them before #52 landed and they were off by one in two places. Measured against the live alert data rather than my earlier arithmetic:

  • 62 advisories open against the root pnpm-lock.yaml right now (the original 64 less the two electron ones chore(deps): bump electron from 41.5.0 to 41.10.3 in /apps/desktop #52 already closed).
  • 56 are cleared by this PR.
  • 6 remain: image-size ×2 (no patched version exists), sharp, uuid, and the two that name packages absent from the lockfile — @vitest/browser and @hono/node-server.

So the split is 4 knowingly deferred and 2 that look stale, not the "5 genuinely open" the description says. The title is updated; the reasoning in the table is unchanged.

@radroid
radroid merged commit 7fc46bb into mainAug 8, 2026
2 checks passed
@radroid
radroid deleted the t3x/dep-security-sweep branch August 8, 2026 06:25
@radroid

Copy link
Copy Markdown
OwnerAuthor

Correction to the description: the last two alerts are not stale. I wrote that @vitest/browser and @hono/node-server "name packages that are not in the lockfile at all." They are both in it. My check used grep -E '^ <pkg>@', and pnpm-lock.yamlsingle-quotes scoped package keys '@vitest/browser@4.1.9': — so the pattern silently matched nothing and I read that as absent. Unscoped packages were unaffected, so the rest of the triage stands.

What they actually are, and why each is still deferred rather than fixed:

@vitest/browser@4.1.9 → 4.1.10 (critical, dev-scoped).4.1.10 declares an exact peer, "vitest": "4.1.10", so it cannot move alone — it drags the whole family, and vitest here comes from vite-plus@0.2.2, which pins 4.1.9 across @vitest/{expect,mocker,runner,snapshot,spy,utils,pretty-format}. Bumping the test runner out from under the fork's only CI gate, to close an advisory in Vitest Browser Mode, which no vite.config.ts in this repo configures, is the wrong trade. It should ride along with the next vite-plus bump.

@hono/node-server@1.19.14 → 2.0.5 (medium, runtime). No 1.x fix exists; the patch is only in 2.0.5. It arrives via @modelcontextprotocol/sdk@1.29.0, which declares "@hono/node-server": "^1.19.9" — 1.x only. SDK 1.30.0 widens that to "^1.19.9 || ^2.0.5", and @anthropic-ai/claude-agent-sdk@0.3.170 already asks for ^1.29.0, so 1.30.0 is inside the range its own dependant wants. That looked like a clean two-line fix and it is not: the SDK is an auto-installed peer, not a regular dependency, so an overrides: entry rewrites the declared peer range (^1.29.0^1.30.0) and leaves the resolved instance at 1.29.0. pnpm update --depth Infinity does not move it either — nothing in this workspace declares the SDK, so there is nothing for update to act on. Landing it needs a full --force re-resolution of the lockfile, which is disproportionate for a Windows-only path traversal in serve-static. I tried it, reverted it, and left it.

So the real remaining count is 6, split 4 deferred with reasons (image-size ×2, sharp, uuid) and these 2 — not "4 deferred and 2 stale".

radroid added a commit that referenced this pull request Aug 8, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
github-actionsBot pushed a commit that referenced this pull request Aug 10, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 10, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 17, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 18, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@radroid
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore(deps): clear 56 of the 62 open transitive advisories in the root lockfile - #56

Merged
radroid merged 2 commits into
mainfrom
t3x/dep-security-sweep
Aug 8, 2026
Merged

chore(deps): clear 56 of the 62 open transitive advisories in the root lockfile#56
radroid merged 2 commits into
mainfrom
t3x/dep-security-sweep

Conversation

@radroid

Copy link
Copy Markdown
Owner

Follow-up to #52. Dependabot opened no PRs for any of these — it generally cannot auto-fix transitive pnpm dependencies — so they had been accumulating untouched.

What moved

Two levers, deliberately in that order, because the cheaper one covers more than it looks.

1. Re-resolution, no config change at all. Several of these were already satisfiable by the ranges their parents declare; the lockfile was just holding a stale resolution. pnpm update -r --lockfile-only cleared astro (7.0.3 → 7.2.0), postcss (8.5.15 → 8.5.26), svgo (4.0.1 → 4.0.2), js-yaml (4.2.0 → 4.3.1) and undici@7 (7.27.1 → 7.29.0). pnpm update wanted to rewrite apps/marketing/package.json's specifier to ^7.2.0 as it went; I reverted that and re-resolved, and 7.2.0 holds under the original ^7.0.3. No package.json in the repo is touched by this PR.

2. Twelve major-scoped overrides: for the rest, appended to the block upstream already maintains in pnpm-workspace.yaml: brace-expansion (all three major lines), builder-util-runtime, fast-uri, form-data, hono, ip-address, path-to-regexp, shell-quote, tar, undici@6. Every key is pinned to a major — "tar@7": ^7.5.21, not tar: ^7.5.21 — so no entry can silently cross a major in a package nothing here imports directly.

Net effect on the lockfile is a shrink of 413 lines: astro 7.2.0 sheds its old remark/rehype/hast pipeline.

What I deliberately did not fix

packageneedswhy not
image-size 1.2.1No patched version exists. Two high advisories, both <= 2.0.2 with no fix published. Nothing to bump to.
sharp 0.34.50.35.0Native binary with prebuilt gyp artifacts and an allowBuilds entry. In 0.x a minor bump is a breaking change; an override here risks the desktop build for one high advisory. Wants its own PR.
uuid 7.0.311.1.1Four majors. It arrives via a deprecated transitive path, so the real fix is dropping whatever still depends on uuid@7, not forcing 11 underneath it.

Two more alerts — @hono/node-server and @vitest/browser (critical) — name packages that are not in the lockfile at all. They look stale and should auto-close once GitHub rescans the default branch after this lands. Worth confirming rather than assuming.

That leaves 5 genuinely open, from 64.

Ledger

pnpm-workspace.yaml becomes row 37. pnpm-lock.yaml goes to risk 67136, five times the next row — and I added a note under the header saying not to read that number at face value: the lockfile is regenerated at every sync rather than merged, so the cost is one pnpm install, not a thousand conflict decisions. The 18-line overrides: block is what actually has to survive a sync, and it is the row to defend.

Verification is CI — typecheck, lint and the full suite. I did not install node_modules locally to run them; this machine is disk-constrained and the resolve was lockfile-only.

@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: f18ac851-bf89-4c45-958a-bf5e111f26ff

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@radroidradroid changed the title chore(deps): clear 57 of 64 transitive advisories in the root lockfilechore(deps): clear 56 of the 62 open transitive advisories in the root lockfileAug 8, 2026
@radroid

Copy link
Copy Markdown
OwnerAuthor

Correcting the counts in the description. I wrote them before #52 landed and they were off by one in two places. Measured against the live alert data rather than my earlier arithmetic:

  • 62 advisories open against the root pnpm-lock.yaml right now (the original 64 less the two electron ones chore(deps): bump electron from 41.5.0 to 41.10.3 in /apps/desktop #52 already closed).
  • 56 are cleared by this PR.
  • 6 remain: image-size ×2 (no patched version exists), sharp, uuid, and the two that name packages absent from the lockfile — @vitest/browser and @hono/node-server.

So the split is 4 knowingly deferred and 2 that look stale, not the "5 genuinely open" the description says. The title is updated; the reasoning in the table is unchanged.

@radroid
radroid merged commit 7fc46bb into mainAug 8, 2026
2 checks passed
@radroid
radroid deleted the t3x/dep-security-sweep branch August 8, 2026 06:25
@radroid

Copy link
Copy Markdown
OwnerAuthor

Correction to the description: the last two alerts are not stale. I wrote that @vitest/browser and @hono/node-server "name packages that are not in the lockfile at all." They are both in it. My check used grep -E '^ <pkg>@', and pnpm-lock.yamlsingle-quotes scoped package keys '@vitest/browser@4.1.9': — so the pattern silently matched nothing and I read that as absent. Unscoped packages were unaffected, so the rest of the triage stands.

What they actually are, and why each is still deferred rather than fixed:

@vitest/browser@4.1.9 → 4.1.10 (critical, dev-scoped).4.1.10 declares an exact peer, "vitest": "4.1.10", so it cannot move alone — it drags the whole family, and vitest here comes from vite-plus@0.2.2, which pins 4.1.9 across @vitest/{expect,mocker,runner,snapshot,spy,utils,pretty-format}. Bumping the test runner out from under the fork's only CI gate, to close an advisory in Vitest Browser Mode, which no vite.config.ts in this repo configures, is the wrong trade. It should ride along with the next vite-plus bump.

@hono/node-server@1.19.14 → 2.0.5 (medium, runtime). No 1.x fix exists; the patch is only in 2.0.5. It arrives via @modelcontextprotocol/sdk@1.29.0, which declares "@hono/node-server": "^1.19.9" — 1.x only. SDK 1.30.0 widens that to "^1.19.9 || ^2.0.5", and @anthropic-ai/claude-agent-sdk@0.3.170 already asks for ^1.29.0, so 1.30.0 is inside the range its own dependant wants. That looked like a clean two-line fix and it is not: the SDK is an auto-installed peer, not a regular dependency, so an overrides: entry rewrites the declared peer range (^1.29.0^1.30.0) and leaves the resolved instance at 1.29.0. pnpm update --depth Infinity does not move it either — nothing in this workspace declares the SDK, so there is nothing for update to act on. Landing it needs a full --force re-resolution of the lockfile, which is disproportionate for a Windows-only path traversal in serve-static. I tried it, reverted it, and left it.

So the real remaining count is 6, split 4 deferred with reasons (image-size ×2, sharp, uuid) and these 2 — not "4 deferred and 2 stale".

radroid added a commit that referenced this pull request Aug 8, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
github-actionsBot pushed a commit that referenced this pull request Aug 10, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 10, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 17, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
radroid added a commit that referenced this pull request Aug 18, 2026
…eep reopened
Fallout from #56, caught by re-checking the alert list after it merged rather than assuming the count only goes down.
Before the sweep the tree had one nanoid@3.3.12, and GHSA #115/#116 against it sat auto-dismissed by GitHub's auto-triage rule — it was scoped as a development dependency. astro 7.2.0 restructured its tree, adding an already-fixed nanoid@3.3.17 alongside the old copy and flipping that copy's scope to runtime, which took it out from under the rule and reopened both alerts.
The sweep did not introduce a vulnerability — 3.3.12 was there before and was always affected — but it turned a suppressed finding into a live one.
One override, "nanoid@3": ^3.3.17, dedupes onto the version already in the tree. Both advisories want <= 3.3.17, so this clears both.
Ledger figures refreshed in the same commit per SEAMS.md's self-reference rule.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@radroid