Repository navigation
chore(deps): override vulnerable transitive dependencies - #276
Conversation
Lift transitive dependencies flagged by open security alerts via pnpm overrides: - undici <6.28.1 (GHSA-rfgv-xxqx-mfg5, GHSA-3wwx-pv8p-q78v, GHSA-r53p-7pc4-xj5r) - fast-uri <3.1.8 (GHSA-qw65-cvwx-89v3, GHSA-58mr-gqgx-xq4g, GHSA-hrr3-gc8f-f4qj) - deepmerge-ts <8 (GHSA-ggr8-5vv4-36mx) - source-map-js <1.2.2 (GHSA-68fv-2mgg-jv7q) - postcss-selector-parser <7.1.6 (GHSA-rj75-hqrm-r3gf) braces (GHSA-vfj7-8cjw-p6xm, via tailwindcss 3) has no patched release yet and stays open. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013PFFqaQmGt6UGbESddu5sz
There was a problem hiding this comment.
Graphify reviewed this change.
Looks safe to merge — no coupling regressions and no blocking issues, checked against the code graph (not a self-assessment).
Graphify review — findings
Tightens the pnpm security overrides to pick up new advisories: undici now floors at 6.28.1 (resolving to 6.29.0 under discord.js) and fast-uri at 3.1.8 (resolving to 3.1.8 under ajv). Adds overrides that force deepmerge-ts to 8.x past @prisma/config's exact 7.1.5 pin, source-map-js to 1.2.2 under postcss, and postcss-selector-parser to 7.1.6 even though tailwindcss 3 and postcss-nested ask for ^6. The two major-version jumps lean on the documented breaking changes not affecting the call sites, since Prisma only calls deepmerge() and the CSS output stays byte-identical.
No blocking issues surfaced.
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 6 functions depend on the 6 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 6 functions in the blast radius were not formally verified this run (proofs are advisory here).
Health delta baseline: last indexed commit bfd9f26, 1 commit(s) behind this PR's base.
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 6 function(s) in the blast radius were not formally verified this run
Description
Fixes the open security alerts for transitive dependencies. The packages that pull them in pin exact or old ranges, so the fixes are applied as
pnpm-workspace.yamloverrides, each documented the same way as the existing entries:Compatibility notes:
@prisma/configonly callsdeepmerge(). The v8 breaking changes (deepmergeIntoaliasing, renamed meta-data types) don't touch it.prisma validateandprisma generatestill pass.apps/webbuilds is byte-identical before and after this change.Not fixable yet:
braces(GHSA-vfj7-8cjw-p6xm, via tailwindcss 3 › chokidar/micromatch). The advisory names>=3.0.4as the fix, but npm's newest release is still 3.0.3. The real way out is moving to Tailwind 4, which is a separate migration.Type of change
Checklist
pnpm lint,pnpm typecheck,pnpm buildpass locally (pnpm testandprisma validate/generateas well).envvalues committedLinked issues
Open Dependabot alerts listed above.
🤖 Generated with Claude Code
https://claude.ai/code/session_013PFFqaQmGt6UGbESddu5sz
Generated by Claude Code