Conversation
`pnpm audit` reported 18 findings (10 high, 7 moderate, 1 low) across seven packages, all new advisories published since the 2026-07-24 `pnpm-workspace.yaml` overrides fix. Bump the four existing overrides and add three new ones, each to the version its own advisories are fixed at: - `brace-expansion` ^5.0.7 -> ^5.0.9 (GHSA-rgw5-rvv9-x895, DoS via unbounded intermediate arrays) - `fast-uri` -> ^3.1.6, new override (GHSA-7p8r-x3mc-p8w7, GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf, GHSA-jqff-g426-hqxp; host-confusion and SSRF issues, pulled in via `ajv`, used by webpack's schema validation) - `js-yaml` ^4.3.0 -> ^4.3.2 (GHSA-5p4m-2wfm-xmqj, GHSA-2883-xcg3-v3hh; quadratic CPU consumption in merge-key/omap handling, pulled in via `webpack-cli`) - `postcss-selector-parser` -> ^7.1.3, new override (GHSA-w9m9-85wc-3x92, DoS via uncontrolled AST recursion, pulled in via `css-loader`'s CSS-modules plugins) - `qs` -> ^6.16.0, new override (GHSA-x5fp-wj9c-mxmx, GHSA-4mjr-xmp4-gh2g; array-limit bypass and isBuffer DoS, pulled in via `webpack-dev-server`'s `express` dependency) - `svgo` ^4.0.2 -> ^4.1.0 (GHSA-w27v-7q3p-w38r, GHSA-4vpr-x523-8j87; `removeScripts` executable-content bypasses, pulled in via the production CSS minification pipeline) - `undici` ^7.28.0 -> ^7.29.0 (GHSA-4cwx-7wf7-3272 plus four moderate advisories; cache/cookie/CRLF handling issues, pulled in via `jsdom` for the mocha test suite's DOM environment) All seven are transitive dependencies of build and test tooling only (webpack, its plugins, and jsdom); none ship in the compiled site bundle. Verified: `pnpm audit` now reports 0 vulnerabilities (was 18). `pnpm run cover` (126 passing, coverage unchanged at 99.94% statements / 97.42% branches), `pnpm run production` (clean compile, unchanged pre-existing bundle-size warnings), and `pnpm run eslint` (0 problems) all behave identically to before the overrides. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
gusthoff
force-pushed
the
dev/topic/infrastructure/pnpm/security-audit-fixes/2026-09-26
branch
from
September 26, 2026 00:00
7721cbe to
92fbeee
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
pnpm auditreported 18 findings (10 high, 7 moderate, 1 low) across seven packages, all new advisories published since the 2026-07-24pnpm-workspace.yamloverrides fix. Bump the four existing overrides and add three new ones.Verified:
pnpm auditnow reports 0 vulnerabilities (was 18).