Skip to content

chore(deps): override vulnerable transitive dependencies - #276

Merged
Musiker15 merged 1 commit into
mainfrom
claude/upbeat-carson-g9anc8
Oct 6, 2026
Merged

Musiker15 merged 1 commit into
mainfrom
claude/upbeat-carson-g9anc8

Conversation

@Musiker15

Copy link
Copy Markdown
Member

Description

Fixes the open security alerts for transitive dependencies. The packages that pull them in pin exact or old ranges, so the fixes are applied as pnpm-workspace.yaml overrides, each documented the same way as the existing entries:

Package Advisories From → To Pulled in by
undici GHSA-rfgv-xxqx-mfg5 (high), GHSA-3wwx-pv8p-q78v, GHSA-r53p-7pc4-xj5r 6.28.0 → 6.29.0 discord.js (bot)
fast-uri GHSA-qw65-cvwx-89v3 (high), GHSA-58mr-gqgx-xq4g (high), GHSA-hrr3-gc8f-f4qj 3.1.6 → 3.1.8 prisma › @prisma/dev › ajv
deepmerge-ts GHSA-ggr8-5vv4-36mx (high) 7.1.5 → 8.0.2 prisma › @prisma/config
source-map-js GHSA-68fv-2mgg-jv7q (high) 1.2.1 → 1.2.2 vite/vitest › postcss
postcss-selector-parser GHSA-rj75-hqrm-r3gf 6.1.4 → 7.1.6 tailwindcss 3, postcss-nested

Compatibility notes:

  • deepmerge-ts 8: @prisma/config only calls deepmerge(). The v8 breaking changes (deepmergeInto aliasing, renamed meta-data types) don't touch it. prisma validate and prisma generate still pass.
  • postcss-selector-parser 7: the only breaking change in 7.0.0 makes insertions during iteration safe. The Tailwind CSS that apps/web builds is byte-identical before and after this change.

Not fixable yet: braces (GHSA-vfj7-8cjw-p6xm, via tailwindcss 3 › chokidar/micromatch). The advisory names >=3.0.4 as the fix, but npm's newest release is still 3.0.3. The real way out is moving to Tailwind 4, which is a separate migration.

Type of change

  • Bugfix
  • New feature
  • Breaking change
  • Refactor / tech debt
  • Docs / CI

Checklist

  • pnpm lint, pnpm typecheck, pnpm build pass locally (pnpm test and prisma validate/generate as well)
  • Tests added/updated (where it makes sense)
  • Prisma migration included (if the schema changed)
  • No secrets / .env values committed
  • Security implications considered (input validation, authz, CSP)
  • Docs updated if architecture is affected

Linked issues

Open Dependabot alerts listed above.

🤖 Generated with Claude Code

https://claude.ai/code/session_013PFFqaQmGt6UGbESddu5sz


Generated by Claude Code

Lift transitive dependencies flagged by open security alerts via pnpm
overrides:
- undici <6.28.1 (GHSA-rfgv-xxqx-mfg5, GHSA-3wwx-pv8p-q78v, GHSA-r53p-7pc4-xj5r)
- fast-uri <3.1.8 (GHSA-qw65-cvwx-89v3, GHSA-58mr-gqgx-xq4g, GHSA-hrr3-gc8f-f4qj)
- deepmerge-ts <8 (GHSA-ggr8-5vv4-36mx)
- source-map-js <1.2.2 (GHSA-68fv-2mgg-jv7q)
- postcss-selector-parser <7.1.6 (GHSA-rj75-hqrm-r3gf)

braces (GHSA-vfj7-8cjw-p6xm, via tailwindcss 3) has no patched release
yet and stays open.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013PFFqaQmGt6UGbESddu5sz
@Musiker15
Musiker15 merged commit c018930 into main Oct 6, 2026
4 checks passed
@Musiker15
Musiker15 deleted the claude/upbeat-carson-g9anc8 branch October 6, 2026 15:24

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).


Graphify review — findings

Tightens the pnpm security overrides to pick up new advisories: undici now floors at 6.28.1 (resolving to 6.29.0 under discord.js) and fast-uri at 3.1.8 (resolving to 3.1.8 under ajv). Adds overrides that force deepmerge-ts to 8.x past @prisma/config's exact 7.1.5 pin, source-map-js to 1.2.2 under postcss, and postcss-selector-parser to 7.1.6 even though tailwindcss 3 and postcss-nested ask for ^6. The two major-version jumps lean on the documented breaking changes not affecting the call sites, since Prisma only calls deepmerge() and the CSS output stays byte-identical.

No blocking issues surfaced.

Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 6 functions depend on the 6 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 6 functions in the blast radius were not formally verified this run (proofs are advisory here).

Health delta baseline: last indexed commit bfd9f26, 1 commit(s) behind this PR's base.

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 6 function(s) in the blast radius were not formally verified this run

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants