Skip to content

fix(dev-1927): bump source-map-js to 1.2.2 - #77

Open
spur-vuln-author[bot] wants to merge 1 commit into
mainfrom
fix/dev-1927
Open

spur-vuln-author[bot] wants to merge 1 commit into
mainfrom
fix/dev-1927

Conversation

@spur-vuln-author

Copy link
Copy Markdown
Contributor

Context

source-map-js is resolved at 1.2.1 in pnpm-lock.yaml (transitive dependency, not declared in any package.json). GHSA-68fv-2mgg-jv7q requires >= 1.2.2. No Dependabot PR exists for this finding. Bumped via a root pnpm.overrides entry (source-map-js: ^1.2.2), then regenerated the lockfile with pnpm install --lockfile-only.

Test evidence

No Dependabot PR existed to replay; constructed from first_patched_version 1.2.2. CI will run on this PR (Linting and Changeset Checks, Unit Tests, CodeQL, Branch name check).

Risk

Low. Patch-level bump (1.2.1 -> 1.2.2) of a small transitive utility package via a lockfile-only override. No source files touched.


@spur-vuln-author spur-vuln-author Bot added the spur-vuln Security vulnerability remediation PR label Oct 7, 2026

@spur-vuln-reviewer spur-vuln-reviewer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified: diff scope limited to package.json + pnpm-lock.yaml (gate3-check.sh PASS, target=source-map-js pr_version=1.2.2 meets required=1.2.2, alert 134, no extra files/deps). No .github/ changes. CI green (Linting, CodeQL x2, Unit Tests all SUCCESS). All commits authored by spur-vuln-author[bot].

@spur-vuln-reviewer

Copy link
Copy Markdown

merge-conflict: this PR was approved and passed all gates, but merging PR #78 (also pnpm-lock.yaml) ahead of it in this same pass changed main such that mergeStateStatus is now DIRTY (merge conflict). The approval stands; not merged. A human must review this (rebase/regenerate the lockfile). This reviewer will not act on this PR again.

[[spur-vuln-reviewer: escalated merge-conflict]]

@spur-vuln-reviewer spur-vuln-reviewer Bot added the hitl Needs human review — automated vuln remediation escalated this label Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hitl Needs human review — automated vuln remediation escalated this spur-vuln Security vulnerability remediation PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants