Repository navigation
fix: security and quality fixes - #477
lornakelly wants to merge 1 commit into
Conversation
✅ Deploy Preview for openworkflow-editor canceled.
|
🦋 Changeset detectedLatest commit: 7ca02ae The changes in this PR will be included in the next version bump. This PR includes changesets to release 2 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
There was a problem hiding this comment.
🟢 Approval recommended
The overrides and lockfile resolutions are consistent and complete.
0 open findings
What changed in this PR
Updates transitive dependencies to patched versions and synchronizes the pnpm lockfile.
Changes:
- Consolidates duplicate overrides.
- Adds patched overrides for five vulnerable dependencies.
- Regenerates corresponding lockfile entries.
| File | Description |
|---|---|
pnpm-workspace.yaml |
Defines consolidated security overrides. |
pnpm-lock.yaml |
Records patched dependency resolutions. |
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
2eba280 to
7ca02ae
Compare
There was a problem hiding this comment.
🟢 Approval recommended
The overrides and lockfile are synchronized, and the dependency updates remain compatible with the repository’s supported Node.js versions.
0 open findings
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
🧠 Review effort: Balanced
Summary
Add a tidied up overrides to address security and quality vulns:
pnpm audit --fixpnpm install --no-frozen-lockfileVerify
pnpm audit