Skip to content

chore: pin ZenNotes 431907df (smol-toml / hono audit fix) - #21

Merged
adibhanna merged 1 commit into
mainfrom
chore/pin-zennotes-431907df
Sep 9, 2026
Merged

adibhanna merged 1 commit into
mainfrom
chore/pin-zennotes-431907df

Conversation

@adibhanna

Copy link
Copy Markdown
Contributor

Keeps the "high-severity production advisories" gate green: the pinned core's lockfile carried smol-toml 1.7.0, which GHSA-7w5x-hrqm-74c2 (high) flagged today and which already turned the Android shell's CI red. Upstream fixed it lockfile-only in ZenNotes/zennotes#760 (smol-toml 1.8.0, hono 4.13.7); this pin follows that squash commit.

Moving past a3e638fc also adopts the 2.47.0 core (Cloud conflict and draft fixes, Excalidraw switching fix, wikilink-to-file fix). The bridge-contract additions since the old pin are optional, so the mobile bridge is unchanged, and vault.ts has nothing to mirror. Based on main rather than release/1.9.8, which is already archived as build 19.

Verified locally: npm run upstream (pin check + typecheck), npm test (33 pass), npm run build with the boot-path modulepreload check.

The pinned core's production audit went red today on smol-toml
GHSA-7w5x-hrqm-74c2 (high), which CI checks against .zennotes-source.
Upstream fixed it lockfile-only in ZenNotes/zennotes#760 (smol-toml
1.8.0, hono 4.13.7); this follows that squash commit. Moving past
a3e638fc also adopts the 2.47.0 core (Cloud conflict and draft fixes,
Excalidraw switching fix, wikilink-to-file fix). The bridge-contract
additions since the old pin are optional, so the mobile bridge is
unchanged, and vault.ts has nothing to mirror. Lands on main rather
than release/1.9.8, which is already archived as build 19.
@adibhanna
adibhanna merged commit 2eefaa9 into main Sep 9, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant