Skip to content

fix(deps): clear frontend transitive security advisories via pnpm overrides (vite, postcss, ws, fast-uri, brace-expansion) - #31

Merged
timothybrown merged 1 commit into
mainfrom
fix/frontend-transitive-cves
Jun 5, 2026
Merged

timothybrown merged 1 commit into
mainfrom
fix/frontend-transitive-cves

Conversation

@timothybrown

Copy link
Copy Markdown
Owner

Clears the remaining open Dependabot security alerts for the frontend. These are all deeply transitive (under vitest/next/orval/happy-dom/eslint) so Dependabot can't auto-open PRs for them — they need a pnpm.overrides pin.

Package From To Advisory Reachability
vite 8.0.3 8.0.14 GHSA-p9ff-h696-f583 / -v2wj-q39q-566r / -4w7w-66w2-5vf9 dev/test only (vitest engine)
postcss 8.4.31 8.5.15 GHSA-qx2v-qp2m-jg93 build-time (Tailwind)
fast-uri 3.1.0 3.1.2 GHSA-q3j6-qgpj-74h6 / -v39h-62p7-jpjc dev (via orval)
ws 8.20.0 8.21.0 GHSA-58qx-3vcg-4xpx dev (via happy-dom)
brace-expansion 5.0.5 5.0.6 GHSA-jxxr-4gwj-5jf2 dev (via eslint)

Notes

  • Exact pins, each the latest version that is both patched and >7 days old — so the repo's minimum-release-age=10080 (7d) cooldown policy is respected. (Ranges didn't work for vite: it's peer-entangled under vitest, and pnpm wouldn't force it off the vulnerable 8.0.3 without an exact pin.)
  • No production dependencies changed — diff is scoped to the 5 targets plus their legitimate ripple (balanced-match/concat-map removed, vitest peer-id restamp, rolldown from the vite bump).
  • Verified locally: 555 vitest tests pass; production build succeeds.

Companion to the backend transitive-CVE PR (#28) and the Dependabot-authored #26/#27.

🤖 Generated with Claude Code

Dependabot can't auto-bump these (deeply transitive under vitest/next/
orval), so pin them to patched, cooldown-mature versions via overrides:

- vite            8.0.3  -> 8.0.14 (dev/test only)
- postcss         8.4.31 -> 8.5.15 (build-time)
- fast-uri        3.1.0  -> 3.1.2  (via orval, dev)
- ws              8.20.0 -> 8.21.0 (via happy-dom, dev)
- brace-expansion 5.0.5  -> 5.0.6  (via eslint, dev)

Exact pins to the latest version that is both patched and >7d old, so
the repo's minimum-release-age (7d) policy is respected. Verified: 555
vitest tests pass, production build succeeds, no production deps changed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@timothybrown
timothybrown merged commit dbcd627 into main Jun 5, 2026
2 checks passed
@timothybrown
timothybrown deleted the fix/frontend-transitive-cves branch June 5, 2026 17:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant