Skip to content

chore: pin ZenNotes 431907df (smol-toml / hono audit fix) - #62

Merged
adibhanna merged 1 commit into
mainfrom
chore/pin-zennotes-431907df
Sep 9, 2026
Merged

adibhanna merged 1 commit into
mainfrom
chore/pin-zennotes-431907df

Conversation

@adibhanna

Copy link
Copy Markdown
Contributor

Fixes the red "Reject high-severity production advisories" step on main: the pinned core's lockfile carried smol-toml 1.7.0, which GHSA-7w5x-hrqm-74c2 (high) flagged today. Upstream fixed it lockfile-only in ZenNotes/zennotes#760 (smol-toml 1.8.0, hono 4.13.7); this pin follows that squash commit.

Moving past a3e638fc also adopts the 2.47.0 core (Cloud conflict and draft fixes, Excalidraw switching fix, wikilink-to-file fix). The bridge-contract additions since the old pin are optional, so the mobile bridge is unchanged, and vault.ts has nothing to mirror.

Verified locally: npm run upstream (pin check + typecheck), npm test (50 pass), npm run build.

The pinned core's production audit went red today on smol-toml
GHSA-7w5x-hrqm-74c2 (high), which CI checks against .zennotes-source.
Upstream fixed it lockfile-only in ZenNotes/zennotes#760 (smol-toml
1.8.0, hono 4.13.7); this follows that squash commit. Moving past
a3e638fc also adopts the 2.47.0 core (Cloud conflict and draft fixes,
Excalidraw switching fix, wikilink-to-file fix). The bridge-contract
additions since the old pin are optional, so the mobile bridge is
unchanged, and vault.ts has nothing to mirror.
@adibhanna
adibhanna merged commit 6759cb2 into main Sep 9, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant