Skip to content

fix(deps): force transitive deps to CVE-patched versions - #58

Merged
nbkdoesntknowcoding merged 1 commit into
mainfrom
fix/force-transitive-security-patches
Jul 8, 2026
Merged

nbkdoesntknowcoding merged 1 commit into
mainfrom
fix/force-transitive-security-patches

Conversation

@nbkdoesntknowcoding

Copy link
Copy Markdown
Owner

Forces transitive CVE deps past their parent caps via pnpm.overrides. All patch-level bumps; api + web build green. Clears undici/hono/form-data/qs/vite/tar/babel/path-to-regexp/yaml Dependabot alerts.

esbuild 0.28.1 was attempted but DROPPED: forcing it to the 0.28 major broke the astro/vite web build ("Transforming destructuring to the configured target environment is not supported yet" against astro's low browser targets). All other overrides land clean.

Deferred majors (astro/drizzle/vitest) intentionally excluded — reachability-cleared.

The in-range Dependabot group could not reach these patched versions because parent packages cap them below the fix. Pin via pnpm.overrides: hono 4.12.25, form-data 4.0.6, qs 6.15.2, vite 6.4.3, tar 7.5.16, @babel/core 7.29.6, path-to-regexp 6.3.0, yaml 2.8.3, undici 6.27/7.28. esbuild 0.28.1 dropped: it broke the astro/vite web build (destructuring-transform error against low browser targets). All patch-level; no reachable code paths affected.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: nbkdoesntknowcoding <nischaybk@theboringpeople.in>
@nbkdoesntknowcoding
nbkdoesntknowcoding merged commit e504c3b into main Jul 8, 2026
7 of 8 checks passed
@nbkdoesntknowcoding
nbkdoesntknowcoding deleted the fix/force-transitive-security-patches branch July 8, 2026 13:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant