Skip to content

chore(deps): resolve audit issues#33100

Open
alexslavr wants to merge 3 commits into25_1from
lavrov/override-deps
Open

chore(deps): resolve audit issues#33100
alexslavr wants to merge 3 commits into25_1from
lavrov/override-deps

Conversation

@alexslavr
Copy link
Copy Markdown
Contributor

No description provided.

@alexslavr alexslavr requested review from a team and Copilot March 30, 2026 15:56
@alexslavr alexslavr self-assigned this Mar 30, 2026
@alexslavr alexslavr added dependencies Pull requests that update a dependency file 25_1 force all tests labels Mar 30, 2026
@alexslavr alexslavr closed this Mar 30, 2026
@alexslavr alexslavr reopened this Mar 30, 2026
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates pnpm overrides and the lockfile to address dependency audit findings by forcing patched versions of vulnerable transitive packages (notably picomatch).

Changes:

  • Add pnpm.overrides entries for picomatch to bump vulnerable ranges to newer patched versions.
  • Regenerate/update pnpm-lock.yaml to reflect the new override resolutions and dependency graph.

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated 5 comments.

File Description
package.json Adds pnpm override rules targeting vulnerable picomatch ranges.
pnpm-lock.yaml Updates resolved picomatch versions and related snapshots to incorporate the overrides.
Files not reviewed (1)
  • pnpm-lock.yaml: Language not supported

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

25_1 dependencies Pull requests that update a dependency file force all tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants