Conversation
Dependency License Review
License distribution
Excluded packages
|
📊 Coverage + size by packagePer-package bundle size on this PR (no JS/TS source changes detected under
"Coverage" is each package's own |
- next 16.3.4 -> 16.3.6 (apollo-docs, apollo-vertex): GHSA-vcvr-r3jv-pc5j (critical, RCE in next/og ImageResponse) - brace-expansion 5.0.9 -> 5.0.12 (surgical lockfile pin, no override): GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7 (high), GHSA-q2hr-2g5m-vwhr (moderate) - js-yaml override >=5.4.1 (resolves 5.4.2): GHSA-r3ph-w7gj-g6xm (moderate) - dompurify override >=3.4.16: GHSA-p98j-92pf-mc4p (low) Version-scoped quarantine exemptions for next@16.3.6 and dompurify@3.4.16 (both < 14 days). All four vetted 2026-09-30: publisher unchanged, tag + diff match advisory, no new deps, lockfile integrity matches registry. Lockfile also dedupes @swc/helpers 0.5.19->0.5.23 and one semver 7.7.4->7.8.5 onto versions already locked. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- undici 7.29.0 -> 7.29.1 (via @semantic-release/github, ^7.0.0): GHSA-w293-vg96-wgc3, GHSA-rfgv-xxqx-mfg5 (high) + 3wwx/pmjh/3xpg/2jfj/rx4f (moderate) + r53p/2gqq/8436 (low) - undici 6.28.0 -> 6.28.1 (via @actions/http-client, ^6.23.0): GHSA-rfgv-xxqx-mfg5 (high), GHSA-3wwx-pv8p-q78v (moderate), GHSA-r53p-7pc4-xj5r (low) - ip-address 10.3.1 -> 10.7.2 (via express-rate-limit, ^10.2.0): GHSA-rpw4-54j3-4h4q, GHSA-2vr4-cq9g-pvrc, GHSA-j6r3-76f7-8jcv, GHSA-h3mg-xc3c-68pw (moderate) - fast-uri override ^3.1.6 -> ^3.1.8 (resolves 3.1.8): GHSA-qw65-cvwx-89v3, GHSA-58mr-gqgx-xq4g (high), GHSA-hrr3-gc8f-f4qj (moderate) undici and ip-address use the surgical pin (override, install, remove, install); parent caret ranges hold the patched versions and overrides: is unchanged for them. All versions > 14 days old, no quarantine exemptions. Vetted 2026-09-30: publisher unchanged, tag + diff match advisories, no new deps, lockfile integrity matches registry. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
3fce792 to
dab7fa9
Compare
|
Apollo Coded App preview deployments are ready.
|
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Supply-chain dependency updates require final human confirmation of package vetting and successful CI.
Review effort: Balanced
Findings: None
What changed in this PR
Updates audited transitive development dependencies, complementing #1258 to clear remaining pnpm audit advisories.
Changes:
- Raises the
fast-urisecurity override to^3.1.8. - Surgically updates vulnerable
fast-uri,ip-address, andundicilockfile resolutions.
| File | Description |
|---|---|
pnpm-workspace.yaml |
Raises and documents the vetted fast-uri override. |
pnpm-lock.yaml |
Pins the four targeted secure dependency versions. |
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
Folded into #1258 as a single squashed commit. |
Summary
Stacked on #1258. With both PRs merged, the full
pnpm audit(dev deps included) exits 0.undici7.x@semantic-release/githubuses^7.0.0undici6.x@actions/http-clientuses^6.23.0ip-addressexpress-rate-limituses^10.2.0fast-uri^3.1.8A surgical pin means adding a temporary override, installing, removing the override and installing again ("Already up to date"). The resulting
overrides:block differs only in thefast-uriline. All versions are older than 14 days, so no quarantine exemptions are needed.Supply-chain vetting (2026-09-30)
index.jsandlib/utils.js, with tests. No dependencies.isGlobal,offset/nextNetwork, IANA classifiers). All 26 commits are by the maintainer, including the 4 fork-merge GHSA fixes; 10.7.2 only adds afromArpafix. No dependencies.integrityfor each package matchesnpm view.Lockfile scope
36 lines change, and every one is one of the four target packages. Nothing else moved.
Test plan
pnpm audit: no known vulnerabilitiespnpm check:dependencies: passesip-addressreaches apollo-vertex through shadcn's MCP SDK)🤖 Generated with Claude Code