Skip to content

fix(dev-1928): bump tinypool to 2.1.2 - #78

Merged
spur-vuln-reviewer[bot] merged 1 commit into
mainfrom
fix/dev-1928
Oct 7, 2026
Merged

spur-vuln-reviewer[bot] merged 1 commit into
mainfrom
fix/dev-1928

Conversation

@spur-vuln-author

Copy link
Copy Markdown
Contributor

Context

tinypool is a transitive dependency (not declared in any package.json), resolved at two separate lines in pnpm-lock.yaml today — 0.8.4 and 1.1.1 — both well below the patched 2.x line. GHSA-5gmw-xhrv-c9v3 (>= 2.1.1) and GHSA-85c8-ppgw-ccpr (>= 2.1.2) both require the 2.x line. No Dependabot PR exists for this finding. Bumped via a root pnpm.overrides entry (tinypool: ^2.1.2), then regenerated the lockfile with pnpm install --lockfile-only; both prior resolutions now consolidate to a single 2.2.0 line.

Test evidence

No Dependabot PR existed to replay; constructed from first_patched_version 2.1.2 (the highest of the two advisories). CI will run on this PR (Linting and Changeset Checks, Unit Tests, CodeQL, Branch name check).

Risk

Medium. This crosses a major version boundary (0.x/1.x -> 2.x) for a transitive test-runner-worker-pool dependency used by vitest. No source files are touched; CI's Unit Tests step is the real compatibility check here, not a judgment call made in advance.


@spur-vuln-author spur-vuln-author Bot added the spur-vuln Security vulnerability remediation PR label Oct 7, 2026

@spur-vuln-reviewer spur-vuln-reviewer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified: diff scope limited to package.json + pnpm-lock.yaml (gate3-check.sh PASS, target=tinypool pr_version=2.2.0 meets required=2.1.2, alerts 132,133, no extra files/deps). No .github/ changes. CI green (Linting, CodeQL x2, Unit Tests all SUCCESS). All commits authored by spur-vuln-author[bot].

@spur-vuln-reviewer
spur-vuln-reviewer Bot merged commit 6e79dc9 into main Oct 7, 2026
5 checks passed
@spur-vuln-reviewer
spur-vuln-reviewer Bot deleted the fix/dev-1928 branch October 7, 2026 02:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

spur-vuln Security vulnerability remediation PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants