Skip to content

fix: security and quality fixes - #477

Open
lornakelly wants to merge 1 commit into
open-workflow-specification:mainfrom
lornakelly:fix/vulnerabilties
Open

lornakelly wants to merge 1 commit into
open-workflow-specification:mainfrom
lornakelly:fix/vulnerabilties

Conversation

@lornakelly

@lornakelly lornakelly commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Add a tidied up overrides to address security and quality vulns:

  • pnpm audit --fix
  • pnpm install --no-frozen-lockfile
  • Removed duplicates

Verify
pnpm audit

No known vulnerabilities found

Copilot AI balanced review requested due to automatic review settings October 9, 2026 10:03
@netlify

netlify Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for openworkflow-editor canceled.

Name Link
🔨 Latest commit 7ca02ae
🔍 Latest deploy log https://app.netlify.com/projects/openworkflow-editor/deploys/6ac8c02fe9a7520008ef0132

@changeset-bot

changeset-bot Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 7ca02ae

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
Name Type
@openworkflowspec/diagram-editor Patch
@openworkflowspec/i18n Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The overrides and lockfile resolutions are consistent and complete.

0 open findings

What changed in this PR

Updates transitive dependencies to patched versions and synchronizes the pnpm lockfile.

Changes:

  • Consolidates duplicate overrides.
  • Adds patched overrides for five vulnerable dependencies.
  • Regenerates corresponding lockfile entries.
File Description
pnpm-workspace.yaml Defines consolidated security overrides.
pnpm-lock.yaml Records patched dependency resolutions.
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Signed-off-by: lornakelly <lornakelly88@gmail.com>
Copilot AI balanced review requested due to automatic review settings October 9, 2026 10:21

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The overrides and lockfile are synchronized, and the dependency updates remain compatible with the repository’s supported Node.js versions.

0 open findings

Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

🧠 Review effort: Balanced

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants